Permissions, Privileges, and Access Controls in Email Subscribers & Newsletters - #VU22765
Published: November 14, 2019
Email Subscribers & Newsletters
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to insecure permission on dashboard and settings. A remote authenticated user with the "edit_post" capability can view and modify settings, such as send new campaigns, view subscriber information, add new users, change settings, and more.