Beta

Report

Webmaster Tools Verification <= 1.2 is vulnerable to Unauthenticated Arbitrary Plugin Deactivation vulnerability

Unauthenticated
Published
2022-10-18

The Webmaster Tools Verification plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmtv_uninstall function in versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to disable arbitrary plugins.

CVSS

Score:6.5

Severity:Medium

Version: 1.2

The plugin vendor has not patched this vulnerability at the moment.