Social Slider Feed <= 2.0.4 - Missing Authorization
2022-08-01 00:00
WPScanTeamStrategic Overview
StatusPatched in 2.0.5
Affected PluginSocial Slider Feed – Social Media Feed & Gallery Widgets
Affected Version
<= 2.0.4CVSS8.8High
CVE
N/AVulnerability Overview
The Social Slider Feed plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.4. This is due to missing capability checks and nonce validation on the 'showPageContent' function. This makes it possible for unauthenticated attackers to trigger feed deletion.
Technical Analysis
REMEDIATION: Update to version 2.0.5, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C