Logo Carousel <= 3.4.1 - Unauthorised Private Post Access

2021-11-22 00:00
apple502j

Vulnerability Overview

The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature

Technical Analysis

REMEDIATION: Update to version 3.4.2, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C