Unsecured Access: Magazine3 Easy Table of Contents Vulnerable to Missing Authorization
CVE-2023-25469
5.4MEDIUM
Summary
The Easy Table of Contents plugin by Magazine3 exhibits a misconfiguration in its access control security settings, which leads to missing authorization checks. This vulnerability can be exploited by an attacker to gain unauthorized access, potentially compromising sensitive content or configurations within the WordPress environment. Affected versions include all releases from n/a up to and including 2.0.45.2, thereby posing significant risks to websites relying on this plugin for managing their content tables.
Affected Version(s)
Easy Table of Contents <= 2.0.45.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafshanzani Suhada (Patchstack Alliance)