Missing Authorization in CoSchedule Headline Analyzer Affects WordPress Plugin
CVE-2023-46195

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 January 2025

What is CVE-2023-46195?

The CoSchedule Headline Analyzer has a missing authorization vulnerability that allows attackers to exploit improperly configured access control settings. This issue could lead to unauthorized access, potentially compromising the security of the application. The affected version ranges from n/a to 1.3.1, underscoring the need for users to assess their installations and update to mitigate potential risks.

Affected Version(s)

Headline Analyzer <= 1.3.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.
CVE-2023-46195 : Missing Authorization in CoSchedule Headline Analyzer Affects WordPress Plugin