Health Check & Troubleshooting <= 1.2.3 - Missing Authorization Checks

2018-01-25 00:00
Julien Legras

Strategic Overview

Status
Patched in 1.2.4
Affected Version<= 1.2.3
CVSS8.8High
CVEN/A
View all Health Check & Troubleshooting vulnerabilities

Vulnerability Overview

The Health Check & Troubleshooting plugin for WordPress is vulnerable to unauthorized execution of AJAX actions by subscriber level users and above in versions up to, and including 1.2.3. This is due to missing capability checks on the various functions hooked via AJAX actions in the plugin and can lead to attackers performing a variety of unauthorized actions.

Technical Analysis

REMEDIATION: Update to version 1.2.4, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C