WordPress Easing Slider plugin <= 3.0.8 - Plugin Settings Reset Vulnerability
CVE-2023-30490

7.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
13 December 2024

Summary

A vulnerability exists in the Easing Slider plugin developed by Matthew Ruddy, which is related to missing authorization checks. This situation allows for improper access control, potentially enabling an attacker to manipulate security settings incorrectly configured in the plugin. The issue is present in Easing Slider versions up to 3.0.8, leaving a window for exploitation of unauthorized access and possible resets of plugin settings.

Affected Version(s)

Easing Slider <= 3.0.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave Jong (Patchstack)
.