CyberRota Analysis
AI-GeneratedThe Builderall for WordPress plugin prior to version 3.0.2 is vulnerable due to a lack of session binding for its public OAuth authentication routes, enabling unauthenticated attackers to manipulate the connection flow. This could lead to the unauthorized overwriting of stored third-party integration access tokens, particularly affecting sites already linked to a paid account. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of unauthorized access to sensitive integrations.
Original NVD Description
The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the site to already be connected to a paid account.