WordPress Slimstat Analytics plugin <= 5.0.5.1 - Broken Access Control vulnerability
CVE-2023-33994

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
13 December 2024

Summary

A vulnerability exists within VeronaLabs' Slimstat Analytics that stems from missing authorization controls, which may allow unauthorized users to exploit incorrectly configured access settings. This issue poses a risk to the security of data managed by Slimstat Analytics, affecting versions from n/a up to 5.0.5.1. Organizations using these versions may face potential breaches due to this misconfiguration, underscoring the importance of implementing proper access control measures.

Affected Version(s)

Slimstat Analytics <= 5.0.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafshanzani Suhada (Patchstack Alliance)
.