Crowdsignal Dashboard <= 3.0.9 - Authorization Bypass
2022-11-17 00:00
Nosa "apapedulimu" ShandyStrategic Overview
StatusPatched in 3.0.10
Affected PluginCrowdsignal Dashboard – Polls, Surveys & more
Affected Version
<= 3.0.9CVSS5.4Medium
CVE
CVE-2022-45069Vulnerability Overview
The Crowdsignal Dashboard plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 3.0.9. This is due to missing authorization checks on the settings page that made it possible for contributor-level attackers to load the ratings settings page and modify the settings.
Technical Analysis
REMEDIATION: Update to version 3.0.10, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C