A missing authorization check in the Dynamic Content Editor REST endpoint allowed any authenticated user with Contributor-level access or above to create ElementsKit dynamic content posts and open the Elementor editor for content owned by other users. Low-privileged accounts could therefore add and modify site content they should not have access... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
Broken access control in dynamic content editor REST API
Reagiere als Erste:r — dein Feedback zählt!
SOCIAL SHARE CARD GENERATOR