Untriaged
Permalink
CVE-2023-50882
5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): NONE
- Availability impact (A): NONE
WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.13.2.
References
Affected products
profilepress
- =<4.13.2
wp-user-avatar
- =<4.13.2
Matching in nixpkgs
-
nixos-unstable -
- nixpkgs-unstable 1.4.1