CVE-2015-9337

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
22/08/2019
Last modified:
26/08/2019

Description

The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cozmoslabs:profile_builder:*:*:*:*:*:wordpress:*:* 2.1.4 (excluding)


References to Advisories, Solutions, and Tools