Crowdsignal Dashboard <= 3.0.9 - Authorization Bypass

Strategic Overview

Status
Patched in 3.0.10
Affected Version<= 3.0.9
CVSS5.4Medium
CVECVE-2022-45069
View all Crowdsignal Dashboard – Polls, Surveys & more vulnerabilities

Vulnerability Overview

The Crowdsignal Dashboard plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 3.0.9. This is due to missing authorization checks on the settings page that made it possible for contributor-level attackers to load the ratings settings page and modify the settings.

Technical Analysis

REMEDIATION: Update to version 3.0.10, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C