Link Library <= 7.2.7 - Missing Authorization Checks

2021-12-30 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 7.2.8
Affected PluginLink Library
Affected Version<= 7.2.7
CVSS5.3Medium
CVECVE-2021-25093
View all Link Library vulnerabilities

Vulnerability Overview

The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

Technical Analysis

REMEDIATION: Update to version 7.2.8, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C