Chamber Dashboard Business Directory <= 3.3.10 - Missing Authorization

Chamber Dashboard Business Directory <= 3.3.10 - Missing Authorization

EntreBase Advisory: The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdash_add_demo_data() function in versions up to, and including, 3.3.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to add demo data.

Read more about this vulnerability: https://www.wordfence.com/threat-intel/vulnerabilities/id/dbddf8a5-57fe-4c70-b564-75e62b96462d?source=api-prod

About the Contributor
Trust & Safety
The Trust & Safety team ensures the EntreBase platform remains compliant, safe, and user-friendly. Focused on risk management and user protection, they work to uphold trust and provide a seamless experience.