CyberRota Analysis
AI-GeneratedThe MailPress plugin for WordPress versions up to 1.5.0 is vulnerable to unauthorized access, allowing unauthenticated attackers to exploit the campaign revision-restore REST endpoint. This vulnerability enables attackers to overwrite a campaign's content by restoring any prior revision, potentially leading to unauthorized modifications of campaign content. WordPress site administrators using the MailPress plugin should prioritize patching this vulnerability to safeguard against potential content manipulation.
Original NVD Description
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision.