The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://wordpress.org/plugins/divebook/#developers | release notes vendor advisory |
https://www.hooperlabs.xyz/disclosures/divebook.php | third party advisory exploit |