Templately <= 2.2.5 - Improper Authorization to Arbitrary Post Deletion

2023-10-16 00:00
Krzysztof Zając

Vulnerability Overview

The Templately plugin for WordPress is vulnerable to unauthorized loss of data due to an improper capability check on the 'delete' REST endpoint in versions up to, and including, 2.2.5. This makes it possible for authenticated attackers to delete arbitrary posts.

Technical Analysis

REMEDIATION: Update to version 2.2.6, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C