Unauthorized Data Modification in LazyLoad Background Images Plugin for WordPress
CVE-2024-12327
4.3MEDIUM
What is CVE-2024-12327?
The LazyLoad Background Images plugin for WordPress is susceptible to unauthorized data modification due to a lack of proper capability checks in the pblzbg_save_settings() function. This vulnerability affects all versions up to and including 1.0.7. Authenticated attackers with Subscriber-level access or higher can exploit this weakness to alter plugin settings, potentially compromising the integrity of the WordPress site.
Affected Version(s)
LazyLoad Background Images * <= 1.0.7