HomeDefault status
unaffected
Any version before 1.0.1
affected
Description
The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.
Problem types
Product status
Any version before 1.0.1
Credits
Beatriz Fresno Naumova (beafn28)
WPScan
References
wpscan.com/...rability/531537f1-5547-4b0f-9e11-3f8a0b2589f5/