CVE-2023-7288 - "Paytium Mollie Payment Forms & Donations Plugin Capability Bypass Stored Data Tampering"

2 days ago 2
ARTICLE AD BOX
CVE ID : CVE-2023-7288
Published : Oct. 16, 2024, 7:15 a.m. | 24 minutes ago
Description : The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change plugin settings.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article