WordPress Booktics Plugin Missing Authorization Vulnerability Allows Unauthenticated Addon Installation
Vulnerability
A vulnerability exists in the Booktics plugin for WordPress, specifically in versions through 1.0.16. The issue arises from a lack of proper capability checks in the 'Extension_Controller::update_item_permissions_check' function. This flaw enables unauthenticated attackers to install addon plugins, leading to unauthorized modification of data.
Impact
Exploitation of this vulnerability allows for the unauthorized installation of addon plugins, which could be used to modify data or potentially introduce malicious functionality to the WordPress site.
Remediation
Users are advised to update the Booktics plugin to version 1.0.17 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
