Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2019-25151: WordPress Plugin Funnel Builder by CartFlows-Create High Converting Sales Funnels For WordPress Privilege Escalation (1.3.0) - Vulnerabilities

The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1.3.0. This makes it possible for authenticated attackers to activate any plugin on the vulnerable service.

CVE
#vulnerability#wordpress#auth

Description

WordPress Plugin Funnel Builder by CartFlows-Create High Converting Sales Funnels For WordPress is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Funnel Builder by CartFlows-Create High Converting Sales Funnels For WordPress version 1.3.0 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 1.3.1 or latest

References****Related Vulnerabilities

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907