WordPress Leads < 1.6.3 - Authorization Bypass
2015-03-31 00:00
James HookerStrategic Overview
Vulnerability Overview
The WordPress Leads plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 1.6.2. This makes it possible for unathenticated attackers to include malicious content in Leads, which may be executed upon viewing in the dashboard at the current logged-in user's level of permissions.
Technical Analysis
REMEDIATION: Update to version 1.6.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C