Shelf Planner WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Data Modification
Vulnerability
A vulnerability exists in the Shelf Planner plugin for WordPress, in all versions through 2.7.0, allowing unauthorized data modification. This issue arises from a lack of proper capability checks on several REST API endpoints, enabling unauthenticated attackers to alter various plugin settings, including the ServerKey and LicenseKey.
Impact
Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially allowing for misuse of the ServerKey and LicenseKey.
Added: Nov 11, 2025, 4:52 AM
Updated: Nov 11, 2025, 4:52 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
7.4remediation
0.0relevance
1.0threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
