WordPress Leads < 1.6.3 - Authorization Bypass

2015-03-31 00:00
James Hooker

Strategic Overview

Status
Patched in 1.6.3
Affected PluginWordPress Leads
Affected Version< 1.6.3
CVSS5.3Medium
CVEN/A
View all WordPress Leads vulnerabilities

Vulnerability Overview

The WordPress Leads plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 1.6.2. This makes it possible for unathenticated attackers to include malicious content in Leads, which may be executed upon viewing in the dashboard at the current logged-in user's level of permissions.

Technical Analysis

REMEDIATION: Update to version 1.6.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C