TROYANOSYVIRUS
Volver a CVEs

CVE-2023-7286

MEDIUM
6.5

Descripcion

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.

Detalles CVE

Puntuacion CVSS v3.16.5
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado10/16/2024
Ultima modificacion10/16/2024
Fuentenvd
Avistamientos honeypot0

This product uses data from the NVD API but is not endorsed or certified by the NVD.