Unsecured Access: Magazine3 Easy Table of Contents Vulnerable to Missing Authorization
CVE-2023-25469

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
9 December 2024

Summary

The Easy Table of Contents plugin by Magazine3 exhibits a misconfiguration in its access control security settings, which leads to missing authorization checks. This vulnerability can be exploited by an attacker to gain unauthorized access, potentially compromising sensitive content or configurations within the WordPress environment. Affected versions include all releases from n/a up to and including 2.0.45.2, thereby posing significant risks to websites relying on this plugin for managing their content tables.

Affected Version(s)

Easy Table of Contents <= 2.0.45.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafshanzani Suhada (Patchstack Alliance)
.