User Feedback WordPress Plugin Missing Authorization Vulnerability in Onboarding Wizard Function
Vulnerability
A vulnerability exists in the User Feedback WordPress plugin, specifically in versions through 1.8.0. The issue arises from a missing capability check in the 'maybe_load_onboarding_wizard' function, allowing unauthorized access to the onboarding wizard page. This flaw enables unauthenticated attackers to view sensitive configuration information, including the administrator's email address.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive configuration data, such as the administrator's email address.
Remediation
Users are advised to update the User Feedback WordPress plugin to version 1.9.0 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
