PT-2023-16356 · WordPress · Rest Api To Miniprogram

·

CVE-2023-0551

·

Publicado

2023-08-16

·

Atualizado

2023-08-22

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions REST API TO MiniProgram WordPress plugin versions through 4.6.1
Description The issue concerns a lack of authorization and CSRF checks in an AJAX action within the REST API TO MiniProgram WordPress plugin. This allows any authenticated users, such as subscribers, to call and delete arbitrary attachments.
Recommendations For versions through 4.6.1, consider disabling the AJAX action related to attachment deletion until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation. Avoid using the plugin's features that involve attachment management until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-0551

Produtos afetados

Rest Api To Miniprogram