logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-0889

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-0889

Description:
Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator
Last updated date:
04/25/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/25/2023
Reference url to background

https://wpscan.com/vulnerability/c39473a7-47fc-4bce-99ad-28d03f41e74e

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy