ClickDesigns WordPress Plugin Missing Authorization Vulnerability for API Key Modification

Vulnerability

A vulnerability exists in the ClickDesigns plugin for WordPress, allowing unauthorized data modification. This issue arises from a lack of capability checks in the 'clickdesigns_add_api' and 'clickdesigns_remove_api' functions, affecting all versions through 1.8.0. As a result, unauthenticated attackers can alter or delete the plugin's API key.

Impact

Exploitation of this vulnerability allows for unauthorized modification or removal of the API key used by the ClickDesigns plugin, potentially leading to unauthorized access or actions within the plugin's functionality.

Remediation

Users can update to version 2.0.0 or a newer patched version to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.