WP Online Contract Missing Authorization Vulnerability in WordPress Plugin
Vulnerability
A vulnerability exists in the WP Online Contract plugin for WordPress, all versions through 5.1.4, due to a lack of proper capability checks in the json_import() and json_export() functions. This flaw allows unauthenticated attackers to import and export the plugin's settings, potentially leading to unauthorized modifications or data exposure.
Impact
Exploitation of this vulnerability could result in unauthorized access to the plugin's settings, allowing attackers to import or export configurations without authentication.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
7.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
