The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/3550ba54-7786-4ad9-aeb1-1c0750f189d0 | third party advisory exploit |
https://plugins.trac.wordpress.org/changeset/2606615/ | third party advisory patch |