Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NDefault status
unaffected
* (semver)
affected
Description
The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings.
Problem types
Product status
* (semver)
Timeline
| 2025-11-03: | Disclosed |
Credits
Abhirup Konwar
References
www.wordfence.com/...-4ec1-49fd-9b0b-c2b1b6908ba8?source=cve
wordpress.org/plugins/dominokit/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.