WF-7681a661-21bd-42fb-ac97-1da808435520-qubely
Qubely <= 1.7.8 - Missing Authorization
mediumMissing Authorization
5.4
CVSS Score
5.4
CVSS Score
medium
Severity
1.7.9
Patched in
596d
Time to patch
Description
The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_options AJAX action that makes it callable via any authenticated user.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LAttack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
None
Confidentiality
Low
Integrity
Low
Availability
Technical Details
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.