ClickDesigns WordPress Plugin Missing Authorization Vulnerability for API Key Modification
Vulnerability
A vulnerability exists in the ClickDesigns plugin for WordPress, allowing unauthorized data modification. This issue arises from a lack of capability checks in the 'clickdesigns_add_api' and 'clickdesigns_remove_api' functions, affecting all versions through 1.8.0. As a result, unauthenticated attackers can alter or delete the plugin's API key.
Impact
Exploitation of this vulnerability allows for unauthorized modification or removal of the API key used by the ClickDesigns plugin, potentially leading to unauthorized access or actions within the plugin's functionality.
Remediation
Users can update to version 2.0.0 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
