The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
The product calls a function, procedure, or routine, but the caller specifies the arguments in an incorrect order, leading to resultant weaknesses.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/d32b2136-d923-4f36-bd76-af4578deb23b | third party advisory vdb entry exploit technical description |