Vulnerabilities > CVE-2024-11334 - Missing Authorization vulnerability in Nes360 MY Contador Lesr

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
nes360
CWE-862

Summary

The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() function in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to export user data.

Vulnerable Configurations

Part Description Count
Application
Nes360
1

Common Weakness Enumeration (CWE)