Description

The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including, 1.1.14. This makes it possible for unauthenticated attackers to call the files directly and perform a wide variety of unauthorized actions such as accessing a site's database and making changes.

INFO

Published Date :

2024-10-16T06:43:34.069Z

Last Modified :

2024-10-16T18:05:18.848Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2019-25215 vulnerability.

Vendors Products
Ari-soft
  • Ari Adminer

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact