leads5050-visitor-insights < 1.0.4 - Unauthenticated Arbitrary License Change

2021-05-07 00:00
Anonymous

Strategic Overview

Status
Patched in 1.0.4
Affected Version< 1.0.4
CVSS5.3Medium
CVEN/A
View all Leads5050 Visitor Insights vulnerabilities

Vulnerability Overview

The Leads5050 Visitor Insights plugin for WordPress is vulnerable to Arbitrary License Change in versions before 1.0.4. This is due to insufficient access control on the leads5050_set_license AJAX action. This makes it possible for unauthenticated attackers to set and modify arbitrary licenses in the plugin settings.

Technical Analysis

REMEDIATION: Update to version 1.0.4, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C