CVE Published: 07/06/2023 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: Wordfence |
Vendor: cartflowswp |
Product: WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce Status : PUBLISHED
CVE-2019-25151 Description
The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1.3.0. This makes it possible for authenticated attackers to activate any plugin on the vulnerable service.
Metrics
CVSS Version: 3.1 |
Base Score: 5.4 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L