Beta

Report

Fantastic Content Protector Free <= 2.6 is vulnerable to Broken Access Control vulnerability

Unauthenticated
Published
2023-04-12

The Fantastic Content Protector Free plugin for WordPress is vulnerable to unauthorized plugin settings reset due to a missing capability check on the update_setting_fantastic_content_protector function in versions up to, and including, 2.6. This makes it possible for unauthenticated attackers to reset this plugin's settings.

CVSS

Score:5.3

Severity:Medium

Version: 2.6

The plugin vendor has not patched this vulnerability at the moment.