CyberRota Analysis
AI-GeneratedThe Fense Proxy & VPN Blocker plugin for WordPress is vulnerable due to inadequate capability checks and nonce validation, allowing unauthorized users to modify data through the fense_bpvt_save_settings() function. This vulnerability enables unauthenticated attackers to delete critical plugin options and transients, potentially disrupting the plugin's functionality and API key management. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access and data manipulation.
Original NVD Description
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_* hooks and unconditionally calls delete_option() on four plugin options and delete_transient() on three transients tied to the plugin's API key cache and settings. This makes it possible for unauthenticated attackers to delete plugin options and transients, effectively resetting the plugin's API key/data cache and forcing the plugin to refetch state.