Logo Slider and Showcase <= 1.3.36 - Settings Update

2021-10-04 00:00
apple502j

Strategic Overview

Status
Patched in 1.3.37
Affected Version< 1.3.37
CVSS6.5Medium
CVECVE-2021-24742
View all Logo Slider and Showcase vulnerabilities

Vulnerability Overview

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.

Technical Analysis

REMEDIATION: Update to version 1.3.37, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C