WordPress Cost Calculator Builder plugin <= 3.1.42 - Broken Access Control vulnerability
CVE-2023-40011
5.4MEDIUM
Summary
The vulnerability in StylemixThemes Cost Calculator Builder arises from a missing authorization flaw that enables attackers to exploit improperly configured access controls. This security weakness can lead to unauthorized actions and access to sensitive information, thereby affecting the integrity of user interactions within the plugin. Versions affected range from the initial release to 3.1.42, highlighting the need for immediate patching and configuration reviews to ensure robust security measures are in place.
Affected Version(s)
Cost Calculator Builder <= 3.1.42
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafshanzani Suhada (Patchstack Alliance)