Vulnerabilities
Vulnerable Software
Volkov:  Security Vulnerabilities
The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit or delete contrast settings. Please note these issues were patched in 0.6.2.8, though it broke functionality and the vendor has not responded to our follow-ups.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-08-29
Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH).This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.5.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-06-09


Contact Us

Shodan ® - All rights reserved