#VU47488 Improper access control in Coditor - Code Editor
Published: October 9, 2020
Coditor - Code Editor
dr.iel
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the coditor_process_ajax() AJAX call. A remote user can bypass implemented security restrictions and modify files inside the "wp-content" folder and list the content.