Unauthorized Data Loss in Nested Pages Plugin for WordPress
CVE-2023-2434
3.8LOW
What is CVE-2023-2434?
The Nested Pages plugin for WordPress has a security flaw due to a missing capability check on its 'reset' function. This vulnerability affects versions up to and including 3.2.3, allowing authenticated attackers with editor-level permissions or higher to reset the plugin settings. As a result, these attackers can potentially manipulate or erase critical data, posing significant risks to website integrity and user data security.
Affected Version(s)
Nested Pages * <= 3.2.3