CyberRota Analysis
AI-GeneratedThe Udimi Tools plugin for WordPress is vulnerable due to a lack of capability checks in the `ajax_disconnect()` and `ajax_connect()` functions, affecting all versions up to 3.2. This vulnerability allows authenticated attackers with Subscriber-level access or higher to delete critical configuration options or overwrite them with malicious data, potentially compromising the site's connection to its Udimi account. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of unauthorized data modification.
Original NVD Description
The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six configuration options — including the API key, connected Udimi user email, and tracking-script payload — effectively disconnecting the site from the configured Udimi account. The companion `ajax_connect()` handler is missing the same checks, allowing the same low-privilege attackers to overwrite those options with an attacker-supplied API key.