prompt_dismiss_notice AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to perform PHP Object Injection attacks. Replyable by Postmatic <= 2.2.9 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injection
REPORT ID: b9f4d26c-d9cc-4875-8d47-43e2f296e118
The plugin contains a Missing Authorization vulnerability due to a missing capability check in the
You need to log in to view the vulnerability details.