The Disable User Login WordPress plugin up to and including 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated malicious users to block (or unblock) users at will.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
brainvire disable user login |