WordPress LC Wizard Plugin Missing Authorization Vulnerability Allowing Settings Change
Vulnerability
A missing authorization vulnerability has been identified in the WordPress LC Wizard plugin, specifically in versions through 2.1.1. This vulnerability arises from incorrectly configured access control security levels, allowing unauthorized users to exploit the issue and change settings.
Impact
Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially allowing for further exploitation or manipulation of the WordPress site.
Remediation
Users of the WordPress LC Wizard plugin should update to version 2.1.2 or later. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
