FancyPost WordPress Plugin Missing Authorization Vulnerability in Shortcode Export
Vulnerability
A vulnerability exists in the FancyPost WordPress plugin, specifically in the 'Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor' version 6.0.0 and prior. The issue arises from a lack of proper capability checks in the 'handle_block_shortcode_export()' function, allowing authenticated users with Subscriber-level access and above to export shortcodes without authorization.
Impact
Exploitation of this vulnerability allows for unauthorized data access, specifically the export of shortcodes, by authenticated users with Subscriber-level access or higher.
Remediation
Users can update to version 6.0.1 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
