QID 730815
Date Published: 2023-06-05
QID 730815: WordPress Plugin WP Data Access Authenticated Privilege Escalation Vulnerability
WordPress Plugin WP Data Access Create professional responsive data tables within minutes.
Due to a lack of authorization checks on the multiple_roles_update function and authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wpda_role[]' parameter during a profile update.
Affected versions:
WP Data Access versions prior to 5.3.8
QID Detection Logic :
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the WP Data Access WordPress plugin.
Successful exploitation of this vulnerability may allow an authenticated attackers with minimal permissions to modify their user role by supplying the 'wpda_role[]' parameter during a profile update.
- WP Data Access Plugin Home Page -
wordpress.org/plugins/wp-data-access/
CVEs related to QID 730815
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WP Data Access Plugin Home Page |
|