QID 150598
Date Published: 2022-11-28
QID 150598: WordPress LoginPress Plugin: Broken Access Control Vulnerability (CVE-2022-41839)
LoginPress Plugin by LoginPress holds a lot of customization fields to change the layout of the login page of WordPress.
Broken Access Control vulnerability in WordPress LoginPress plugin on WordPress leading to unauth changing of Opt-In or Opt-Out tracking settings.
Affected Versions:
WordPress LoginPress Plugin before 1.6.2
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability may allow non-administrators to change Opt-In or Opt-Out tracking settings.
Solution
Customers are advised to upgrade to LoginPress Plugin 1.6.2 or later version to remediate this vulnerability.
CVEs related to QID 150598
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Patchstack |
|