CyberRota Analysis
AI-GeneratedThe WPC Admin Columns plugin for WordPress prior to version 2.3.4 lacks proper authorization checks in its AJAX actions, enabling users with minimal permissions, such as subscribers, to access sensitive metadata related to users, posts, and terms, including that of administrators. This vulnerability poses a significant risk of data exposure and privacy breaches. WordPress site administrators and security teams should prioritize updating this plugin to mitigate potential unauthorized access to sensitive information.
Original NVD Description
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.