Timeline Block WordPress Plugin Insecure Direct Object Reference Vulnerability
Vulnerability
A vulnerability allowing Insecure Direct Object Reference has been identified in the Timeline Block – Beautiful Timeline Builder for WordPress plugin, affecting all versions up to and including 1.3.3. The issue arises in the tlgb_shortcode() function, where insufficient validation on a user-controlled key allows authenticated attackers with Author-level access and above to access private timeline content by manipulating the id attribute of the 'timeline_block' shortcode.
Impact
Exploitation of this vulnerability could lead to unauthorized disclosure of private timeline content.
Remediation
Users can update to Timeline Block version 1.3.4, which addresses this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
