Data Loss Vulnerability in ImageMapper Plugin for WordPress
CVE-2023-5506
5.4MEDIUM
What is CVE-2023-5506?
The ImageMapper plugin for WordPress is susceptible to a vulnerability that allows authenticated users with subscriber-level permissions and above to delete arbitrary posts and pages. This is due to a missing capability check in the 'imgmap_delete_area_ajax' function, which allows attackers to exploit the flaw and result in unauthorized loss of data. Users of versions up to and including 1.2.6 are at risk and should take immediate action to secure their sites.
Affected Version(s)
ImageMapper * <= 1.2.6