User Rights Access Manager <= 1.0.7 - Access Restriction Bypass
2021-08-05 00:00
AnonymousStrategic Overview
StatusPatched in 1.0.8
Affected PluginUser Rights Access Manager
Affected Version
<= 1.0.7CVSS7.2High
CVE
N/AVulnerability Overview
The User Rights Access Manager plugin for WordPress is vulnerable to Access Restriction Bypass via the 'page' parameter in versions up to, and including, 1.0.7. This makes it possible for admin+ attackers to gain full site access even when certain web pages have been disabled.
Technical Analysis
REMEDIATION: Update to version 1.0.8, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C