Description
The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including, 1.1.14. This makes it possible for unauthenticated attackers to call the files directly and perform a wide variety of unauthorized actions such as accessing a site's database and making changes.
INFO
Published Date :
2024-10-16T06:43:34.069Z
Last Modified :
2024-10-16T18:05:18.848Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2019-25215 vulnerability.
| Vendors | Products |
|---|---|
| Ari-soft |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2019-25215.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact