HomeDefault status
unaffected
Any version before 1.6.1
affected
Description
The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 1.6.1
Credits
yiğit ibrahim sağlam
WPScan
References
wpscan.com/...rability/c42dbab9-b729-4748-88e5-0bd2f6d66e3d/