Beta

Report

Mark New Posts <= 7.5.1 is vulnerable to Broken Access Control vulnerability

Subscriber
Published
2024-12-10

The Mark New Posts plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options() function in versions up to, and including, 7.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to change plugin settings.

CVSS

Score:5.4

Severity:Medium

Version: 7.5.1

There is a patch available in v7.6 and we strongly recommend you update to this version as soon as possible.