CVE-2023-5737

All FrameworksWordPressCWE-OtherCVE-2023-5737

CVE-2023-5737

State: PUBLISHED · Published: 2023-11-27 · Updated: 2024-08-02 · Assigner: WPScan
Description
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/5xxx/CVE-2023-5737.json