CVSS Summary
| Score | 4.3 Medium |
|---|---|
| Vector | Network |
| Complexity | Medium |
| Authentication | None |
| Confidentiality | None |
| Integrity | None |
| Availability | Partial |
Last revised:
An attacker can cause an admin user to remove players if they can convince them to visit an URL of their choice.
Current state: Reported
| Score | 4.3 Medium |
|---|---|
| Vector | Network |
| Complexity | Medium |
| Authentication | None |
| Confidentiality | None |
| Integrity | None |
| Availability | Partial |
Log in as admin, create a new player, visit this URL (changing localhost, and changing player_id to the ID of the player you just created):
http://localhost/wp-admin/admin.php?page=jwp6_menu&player_id=1&action=delete
Disable the plugin until a fix is available.