Buzz Club WordPress Theme Missing Authorization Vulnerability Allowing Arbitrary Option Updates
Vulnerability
A vulnerability exists in the Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme, in all versions through 2.0.4. The issue arises from a missing capability check in the 'cmsmasters_hide_admin_notice' function, allowing authenticated attackers with Subscriber-level access and above to unauthorizedly modify option values. This could lead to a denial-of-service condition by causing errors on the site or by manipulating options related to user registration.
Impact
Exploitation of this vulnerability could result in unauthorized data modification, potentially causing errors that disrupt normal site operations and create a denial-of-service condition for users.
Remediation
Users are advised to update the theme to version 2.0.5 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
