First published: Tue Dec 26 2023(Updated: )
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
<1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.