Description
The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option', 'wploti_remove_whitelisted_users_option', and 'wploti_uploaded_animation_save_option' functions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify certain plugin settings.
Problem types
CWE-284 Improper Access Control
Product status
* (semver)
Timeline
| 2024-12-19: | Disclosed |
Credits
Francesco Carlucci
References
www.wordfence.com/...-198c-4a32-883d-3f90dd399aee?source=cve
plugins.trac.wordpress.org/...ploti_maintenance_redirect.php