Lucene search

K
nvd[email protected]NVD:CVE-2023-5509
HistoryNov 20, 2023 - 7:15 p.m.

CVE-2023-5509

2023-11-2019:15:09
CWE-863
web.nvd.nist.gov
2
wordpress
plugin
authorization
vulnerability
ajax
user action.

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

EPSS

0

Percentile

13.3%

The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.

Affected configurations

Nvd
Node
premiomystickymenuRange<2.6.5wordpress
VendorProductVersionCPE
premiomystickymenu*cpe:2.3:a:premio:mystickymenu:*:*:*:*:*:wordpress:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

EPSS

0

Percentile

13.3%