IgnitionDeck Crowdfunding Platform <= 1.1.6 - Missing Authorization

2015-03-06 00:00
James Golovich

Strategic Overview

Status
Patched in 1.1.7
Affected Version<= 1.1.6
CVSS7.3High
CVEN/A
View all IgnitionDeck Crowdfunding Platform vulnerabilities

Vulnerability Overview

The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.6. This is due to missing capability checks on various functions called via AJAX actions. This makes it possible for unauthenticated attackers to execute various AJAX actions including one that would grant the attacker various permissions that could be used to modify many of the plugin's settings and features.

Technical Analysis

REMEDIATION: Update to version 1.1.7, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C