PT-2023-16382 · WordPress · Vk Blocks

+1

·

CVE-2023-0583

·

Publicado

2023-06-03

·

Atualizado

2023-06-09

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions VK Blocks plugin for WordPress versions up to, and including, 1.57.0.5
Description The issue concerns improper authorization via the REST update vk blocks options function. This allows authenticated attackers with contributor-level permissions or above to change plugin settings, including default icons.
Recommendations For versions up to, and including, 1.57.0.5, update to a version that contains a fix for this issue to prevent unauthorized changes to plugin settings. As a temporary workaround, consider restricting access to the update vk blocks options function until a patch is available.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0583

Produtos afetados

Vk Blocks