wo_remove_client AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to delete arbitrary client. WP OAuth Server by Justin Greer <= 4.2.5 - Missing Authorization to Authenticated (Subscriber) Arbitrary Client Deletion
REPORT ID: f5e7e8e4-24fd-419e-ad80-ee378d249f80
The plugin contains a Missing Authorization vulnerability due to an incorrect capability check in the
You need to log in to view the vulnerability details.