CVE · Medium

CVE-2023-6751 — Hostinger Tools [hostinger] < 1.9.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6751 Hostinger Tools [hostinger] < 1.9.8 Missing Authorization Medium 6.5 < 1.9.8 1.9.8 2024-01-05

CVE-2023-6751

The Hostinger Tools WordPress plugin in versions prior to 1.9.8 contains a broken access control vulnerability that was discovered by Lucio Sá. The plugin fails to properly verify user authorization and authentication checks in certain functions, allowing unauthenticated or low-privileged users to perform actions restricted to higher-privilege accounts. This flaw was resolved in version 1.9.8 and users should update immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.