Summary
Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1.
Risk profile
7.5 · H I G H
CVSS assessment
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack vector
- N E T W O R K
- Complexity
- L O W
- Privileges
- N O N E
- User interaction
- N O N E
- Scope
- U N C H A N G E D
- Confidentiality
- H I G H
- Integrity
- N O N E
- Availability
- N O N E
Weaknesses
-
Missing Authorization
CWE-862
Further reading
1
source