The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1.3.0. This makes it possible for authenticated attackers to activate any plugin on the vulnerable service.
References
Configurations
Information
Published : 2023-06-07 02:15
Updated : 2023-08-09 17:12
NVD link : CVE-2019-25151
Mitre link : CVE-2019-25151
JSON object : View
Products Affected
cartflows
- cartflows
CWE
CWE-269
Improper Privilege Management
