The Qubely WordPress plugin before 1.7.8 does not have...
Moderate severity
Unreviewed
Published
Jan 25, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jan 24, 2022
Published to the GitHub Advisory Database
Jan 25, 2022
Last updated
Jan 29, 2023
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
References