SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-0328

This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).

MEDIUM 4.3EPSS 0.80%

Does this matter?

Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.

Description

The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.80% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
wpcode/wpcode
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.