LazyLoad Background Images WordPress Plugin Missing Authorization Vulnerability in Settings Update
Vulnerability
A vulnerability exists in the LazyLoad Background Images WordPress plugin, all versions through 1.0.7, allowing unauthorized data modification. The issue arises from a lack of capability checks in the 'pblzbg_save_settings()' function. This flaw enables authenticated attackers with Subscriber-level access and above to alter the plugin's settings.
Impact
Exploitation of this vulnerability allows for unauthorized modification of the plugin's settings by authenticated users with Subscriber-level access or higher.
Remediation
No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
