Lucene search

K
cveWordfenceCVE-2023-6369
HistoryJan 11, 2024 - 9:15 a.m.

CVE-2023-6369

2024-01-1109:15:48
CWE-862
Wordfence
web.nvd.nist.gov
48
cve-2023-6369
vulnerability
wordpress
plugin
data access
data modification
ajax actions
nvd

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

31.0%

The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 2.1.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose sensitive information or perform unauthorized actions, such as saving advanced plugin settings.

Affected configurations

Nvd
Vulners
Node
myrecorpexport_wp_page_to_static_html\/cssRange2.1.9wordpress
VendorProductVersionCPE
myrecorpexport_wp_page_to_static_html\/css*cpe:2.3:a:myrecorp:export_wp_page_to_static_html\/css:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "recorp",
    "product": "Export WP Page to Static HTML/CSS",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.1.9",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

References

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

31.0%

Related for CVE-2023-6369