Lucene search

K
cvelistPatchstackCVELIST:CVE-2023-47754
HistoryDec 18, 2023 - 11:49 p.m.

CVE-2023-47754 WordPress Delete Duplicate Posts Plugin <= 4.8.9 is vulnerable to Broken Access Control

2023-12-1823:49:12
CWE-862
Patchstack
www.cve.org
1
cve-2023-47754
wordpress
delete duplicate posts
broken access control
missing authorization
clever plugins

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

9.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.1%

Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Delete Duplicate Posts: from n/a through 4.8.9.

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "delete-duplicate-posts",
    "product": "Delete Duplicate Posts",
    "vendor": "Clever plugins",
    "versions": [
      {
        "changes": [
          {
            "at": "4.9",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "4.8.9",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

9.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.1%

Related for CVELIST:CVE-2023-47754