CVE-2023-0328
Published on: Not Yet Published
Last Modified on: 03/11/2023 02:58:00 AM UTC
Certain versions of Wpcode from Wpcode contain the following vulnerability:
The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).
- CVE-2023-0328 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Unknown - WPCode version < 2.0.7
CVSS3 Score: 4.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Just a moment... | wpscan.com text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Wpcode | Wpcode | All | All | All | All |
- cpe:2.3:a:wpcode:wpcode:*:*:*:*:*:wordpress:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-0328 : The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for sever… twitter.com/i/web/status/1… | 2023-03-06 14:09:06 |
![]() |
Potentially Critical CVE Detected! CVE-2023-0328 The WPCode WordPress plugin before 2.0.7 does not have adequate pr… twitter.com/i/web/status/1… | 2023-03-06 15:11:01 |