Privilege Escalation Vulnerability in Leyka
CVE-2023-33327

8.8HIGH

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
14 May 2024

Summary

The Teplitsa Leyka Plugin has a vulnerability related to improper privilege management, which may allow a user with limited permissions to escalate their privileges. This can potentially lead to unauthorized access and modifications within the application. Users of Leyka are strongly advised to update to the latest version to mitigate potential risks and enhance their security posture.

Affected Version(s)

Leyka <= 3.30.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tien Nguyen Anh (Patchstack Alliance)
.