Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

2019-02-25 00:00
Anonymous

Strategic Overview

Status
Patched in 1.9.3
Affected PluginUltimeter
Affected Version< 1.9.3
CVSS8.8High
CVEN/A
View all Ultimeter vulnerabilities

Vulnerability Overview

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and potentially take over the site.

Technical Analysis

REMEDIATION: Update to version 1.9.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C