Unauthorized Data Modification in Go Pricing Plugin for WordPress
CVE-2023-2494
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 24 May 2023
What is CVE-2023-2494?
The Go Pricing - WordPress Responsive Pricing Tables plugin is susceptible to unauthorized data modifications due to a missing capability check in the 'process_postdata' function. This vulnerability could allow authenticated users with inappropriate privileges to alter the plugin's settings and access, undermining the administrator's exclusive control over sensitive functionalities. Users are advised to update to the latest version to safeguard against potential exploitation.
Affected Version(s)
Go Pricing - WordPress Responsive Pricing Tables * <= 3.3.19