#VU21334 Improper access control in Rich Reviews
Published: September 25, 2019
Rich Reviews
Nuanced Media
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions when processing data passed to the "/wp-admin/admin-post.php" URL. A remote non-authenticated attacker can bypass implemented security restrictions and execute arbitrary JavaScript code on the website.
Note: this vulnerability is being actively exploited in the wild.