The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/1854f77f-e12a-4370-9c44-73d16d493685 | third party advisory vdb entry exploit technical description |