Vulnerabilities > CVE-2020-9514 - Missing Authorization vulnerability in Idxbroker Impress for IDX Broker
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in user (with the Subscriber role) to permanently delete arbitrary posts and pages, create new posts with arbitrary subjects, and modify the subjects of existing posts and pages (via create_dynamic_page and delete_dynamic_page).
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://wordpress.org/plugins/idx-broker-platinum/#developers
- https://wordpress.org/plugins/idx-broker-platinum/#developers
- https://www.wordfence.com/blog/2020/03/vulnerabilities-patched-in-impress-for-idx-broker/
- https://www.wordfence.com/blog/2020/03/vulnerabilities-patched-in-impress-for-idx-broker/