PT-2024-14923 · WordPress · Woostify Sites Library

·

CVE-2023-6279

·

Published

2024-01-29

·

Updated

2026-02-20

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Woostify Sites Library WordPress plugin versions prior to 1.4.8
Description The issue concerns a lack of authorization in an AJAX action, allowing any authenticated users to update arbitrary blog options and set them to 'activated'. This could potentially lead to a Denial of Service (DoS) when using a specific option name.
Recommendations For versions prior to 1.4.8, update to version 1.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action to prevent unauthorized updates to blog options.

Exploit

Fix

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-6279

Affected Products

Woostify Sites Library