User Rights Access Manager <= 1.0.7 - Access Restriction Bypass

2021-08-05 00:00
Anonymous

Strategic Overview

Status
Patched in 1.0.8
Affected Version<= 1.0.7
CVSS7.2High
CVEN/A
View all User Rights Access Manager vulnerabilities

Vulnerability Overview

The User Rights Access Manager plugin for WordPress is vulnerable to Access Restriction Bypass via the 'page' parameter in versions up to, and including, 1.0.7. This makes it possible for admin+ attackers to gain full site access even when certain web pages have been disabled.

Technical Analysis

REMEDIATION: Update to version 1.0.8, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C