Temporary Login Without Password <= 1.7.0 - Subscriber+ Plugin Settings Update

2021-11-15 00:00
apple502j

Strategic Overview

Status
Patched in 1.7.1
Affected Version<= 1.7.0
CVSS4.3Medium
CVECVE-2021-24836
View all Temporary Login Without Password vulnerabilities

Vulnerability Overview

The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them

Technical Analysis

REMEDIATION: Update to version 1.7.1, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C