WP-Filebase <= 0.2.9.24 - Missing Authorization Checks

2012-11-13 00:00
Anonymous

Strategic Overview

Status
Patched in 0.2.9.25
Affected PluginWP-Filebase
Affected Version<= 0.2.9.24
CVSS7.3High
CVEN/A
View all WP-Filebase vulnerabilities

Vulnerability Overview

The WP-Filebase plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'del' & 'cats' actions in versions up to, and including, 0.2.9.24. This makes it possible for attackers to perform unauthorized actions such as deleting files and categories.

Technical Analysis

REMEDIATION: Update to version 0.2.9.25, or a newer patched version

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C