The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-12-08T19:46:28

Updated: 2024-08-04T12:39:36.203Z

Reserved: 2020-06-16T00:00:00

Link: CVE-2020-14205

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-08T20:15:15.167

Modified: 2024-11-21T05:02:51.940

Link: CVE-2020-14205

cve-icon Redhat

No data.