CVE-2017-18543

The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
References
Link Resource
https://wordpress.org/plugins/invite-anyone/#developers Issue Tracking Third Party Advisory
https://wordpress.org/plugins/invite-anyone/#developers Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:invite_anyone_project:invite_anyone:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 03:20

Type Values Removed Values Added
References () https://wordpress.org/plugins/invite-anyone/#developers - Issue Tracking, Third Party Advisory () https://wordpress.org/plugins/invite-anyone/#developers - Issue Tracking, Third Party Advisory

Information

Published : 2019-08-16 21:15

Updated : 2024-11-21 03:20


NVD link : CVE-2017-18543

Mitre link : CVE-2017-18543

CVE.ORG link : CVE-2017-18543


JSON object : View

Products Affected

invite_anyone_project

  • invite_anyone
CWE
CWE-284

Improper Access Control