Beta

Report

10WebAnalytics <= 1.2.12 is vulnerable to Broken Access Control vulnerability

Subscriber
Published
2023-11-14

The 10WebAnalytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gawd_wd_bp_install_notice_status function in versions up to, and including, 1.2.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss admin notifications.

CVSS

Score:4.3

Severity:Medium

Version: 1.2.12

The plugin vendor has not patched this vulnerability at the moment.