The Workreap WordPress theme before 2.6.4 does not verify...
Moderate severity
Unreviewed
Published
Dec 26, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Dec 26, 2022
Published to the GitHub Advisory Database
Dec 26, 2022
Last updated
Jan 28, 2023
The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.
References