SB2020090704 - Privilege escalation in NextScripts: Social Networks Auto-Poster plugin for WordPress
Published: September 7, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: N/A)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote authenticated attacker can remove posts (by corrupting the post type and other data), post arbitrary information in the site social networks and change the plugin settings.
Remediation
Install update from vendor's website.