Image Source Control Lite < 2.3.1 - Insecure Direct Object Reference

2021-10-04 00:00
apple502j

Strategic Overview

Vulnerability Overview

The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit).

Technical Analysis

REMEDIATION: Update to version 2.3.1, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C