The spectra-popup post type and its meta fields were exposed via the REST API with auth_callback __return_true, letting unauthenticated visitors read popups and their settings. The fix requires manage_options. This vulnerability affects the following application versions: Spectra – WordPress Gutenberg Blocks 2.6.0 Spectra – WordPress Gutenberg... Weiterlesen
Intelligence View
Incorrect Permissions in Spectra Popup Builder REST Endpoints
The spectra-popup post type and its meta fields were exposed via the REST API with auth_callback __return_true, letting unauthenticated visitors read popups and their settings. The fix requires manage_options. This vulnerability affects…
SOCIAL SHARE CARD GENERATOR