CVE-2023-6883
Description
The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 6.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions, such as modifying the plugin's Facebook and Instagram access tokens and updating group IDs.
CWE
- CWE-862 — CWE-862 Missing Authorization
Affected
- sjaved / Easy Social Feed – Social Photos Gallery and Post Feed for WordPress — v=0 ≤6.5.2 [affected]
CVSS
- 3.1 score=4.3 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3deee9b5-2e36-447d-a492-e22e3dc6a5ab?source=cve
- https://plugins.trac.wordpress.org/changeset/3012165/easy-facebook-likebox
Source
cvelistV5-main/cves/2023/6xxx/CVE-2023-6883.json