CVE-2023-6751
The Hostinger Tools WordPress plugin in versions prior to 1.9.8 contains a broken access control vulnerability that was discovered by Lucio Sá. The plugin fails to properly verify user authorization and authentication checks in certain functions, allowing unauthenticated or low-privileged users to perform actions restricted to higher-privilege accounts. This flaw was resolved in version 1.9.8 and users should update immediately.
Based on public CVE data (MITRE/NVD).