WF-7681a661-21bd-42fb-ac97-1da808435520-qubely

Qubely <= 1.7.8 - Missing Authorization

mediumMissing Authorization
5.4
CVSS Score
5.4
CVSS Score
medium
Severity
1.7.9
Patched in
596d
Time to patch

Description

The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_options AJAX action that makes it callable via any authenticated user.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
None
Confidentiality
Low
Integrity
Low
Availability

Technical Details

Affected versions<=1.7.8
PublishedJune 6, 2022
Last updatedJanuary 22, 2024
Affected pluginqubely

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.