Arbitrary Post Manipulation in IMPress for IDX Broker Plugin by WordPress
CVE-2020-9514
6.5MEDIUM
Summary
A security issue in the IMPress for IDX Broker plugin prior to version 2.6.2 allows logged-in users with Subscriber roles to execute unauthorized actions. This includes the ability to permanently delete existing posts and pages, create new posts with arbitrary titles, and alter the titles of existing posts and pages. Such vulnerabilities can lead to potential misuse of website content and disruption of services.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved