WordPress Super Socializer plugin <= 7.13.54 - Broken Access Control vulnerability
CVE-2023-41802

4.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
13 December 2024

Summary

The Heateor Super Socializer plugin is susceptible to a missing authorization vulnerability, which stems from incorrectly configured access control security levels. This flaw permits unauthorized access to certain functionalities, potentially allowing unprivileged users to exploit the system and manipulate sensitive data or features within the plugin's environment. The vulnerability impacts all versions from n/a through 7.13.54, highlighting the necessity for users to review their access control settings to mitigate risks associated with this oversight.

Affected Version(s)

Super Socializer <= 7.13.54

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafshanzani Suhada (Patchstack Alliance)
.