CVSS Summary
| Score | 4.3 Medium | 
|---|---|
| Vector | Network | 
| Complexity | Medium | 
| Authentication | None | 
| Confidentiality | None | 
| Integrity | Partial | 
| Availability | None | 
Last revised:
WP User Groups creates new bulk actions to put users into (or remove them from) “groups” and “types”. A nonce is sent with the request, but it is not checked.
Current state: Fixed
| Score | 4.3 Medium | 
|---|---|
| Vector | Network | 
| Complexity | Medium | 
| Authentication | None | 
| Confidentiality | None | 
| Integrity | Partial | 
| Availability | None | 
Upgrade to version 2.1.1 or later.