Soumettre.fr WordPress Plugin Improper Authorization Vulnerability Allowing Unauthenticated Post Manipulation
Vulnerability
A vulnerability exists in the Soumettre.fr plugin for WordPress, in all versions through 2.1.5, due to inadequate authorization checks in the make_signature function. This flaw allows unauthenticated users to create, edit, or delete Soumettre posts. The issue arises only when the Soumettre account is not connected, meaning the API key is not installed.
Impact
Exploitation of this vulnerability allows for unauthorized creation, modification, and deletion of Soumettre posts by unauthenticated users.
Added: Jul 2, 2025, 4:45 AM
Updated: Jul 2, 2025, 4:45 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
8.1remediation
0.0relevance
0.2threat
3.2urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
