Sceawere
Vulnerability Detail
CVE-2026-97303UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Missing Authorization in Scratch & Win
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 2h ago
- Vendor
- Apps Mav
- Product
- Scratch & Win – Giveaways and Contests
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-10-05T19:17:27.267Z",
"pubdate": "2026-10-05T19:17:27.267Z",
"executiveSummary": "The Scratch & Win – Giveaways and Contests plugin for WordPress is vulnerable to a Missing Authorization flaw, classified under improper access control.\nThis vulnerability allows unauthorized users to perform actions restricted to administrative or privileged roles by exploiting incorrectly configured access control checks within the plugin.\nThe flaw affects all versions of the product from n/a through 3.0.2.\nThe vulnerability poses a significant risk to data integrity and administrative control, as an unauthenticated or low-privileged attacker can manipulate plugin configurations, giveaways, or contest settings.\nSuccessful exploitation does not require advanced technical prerequisites beyond the ability to send crafted HTTP requests to the affected application interface.\nThe impact includes potential unauthorized data modification and administrative setting changes, potentially leading to a compromise of the contest and giveaway management functionality within the WordPress environment.",
"technicalDetails": "The root cause of this vulnerability lies in the failure of the plugin to implement adequate authorization checks (e.g., capability checks like current_user_can()) on sensitive administrative functions.\nIn the affected versions (n/a through 3.0.2), the application fails to verify the identity and permissions of the user initiating a request before processing requests related to contest settings and giveaway configurations.\nThe vulnerability manifests as an insecure direct object reference or an unauthenticated API/action endpoint exposure. Because the plugin does not validate user capabilities against the requested action, the system executes the requested logic despite the user lacking the necessary administrative privileges.\nThe attack flow involves an attacker identifying the specific request parameters (such as action hooks or AJAX/REST API endpoints) used by the plugin to modify contest data. By crafting a request that mirrors the structure of a legitimate administrative action and sending it to the server, the attacker can manipulate plugin data.\nSince the backend fails to perform an access control check, the server-side code proceeds to execute the function associated with the request as if it were initiated by an authorized administrator.\nThis behavior exposes the underlying application logic to unauthorized state changes. Post-exploitation, an attacker can modify giveaway parameters, delete contest entries, or alter plugin settings, effectively bypassing intended security constraints. This effectively grants an attacker the ability to manage the contest and giveaway infrastructure without legitimate credentials.\nThe vulnerability is reachable via standard web requests, requiring no specific network position other than accessibility to the WordPress instance. The lack of validation occurs at the plugin component level, ensuring that any user, regardless of their role or authentication status, may potentially trigger these functions."
}