Beta

Report

DiveBook <= 1.1.4 is vulnerable to Improper Authorisation Check vulnerability

Unauthenticated
Published
2020-12-08

The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.

CVSS

Score:5.3

Severity:Medium

Version: 1.1.4

There is a patch available in v1.5.5 and we strongly recommend you update to this version as soon as possible.