Missing Authorization Vulnerability in WP iCal Availability Plugin
CVE-2023-46607
5.4MEDIUM
Summary
A missing authorization vulnerability in the WP iCal Availability plugin allows attackers to exploit incorrectly configured access control security levels. This issue permits unauthorized users to access functions intended for authenticated users, potentially leading to unauthorized information disclosure or manipulation. The affected versions include WP iCal Availability up to 1.0.3, emphasizing the need for security measures in WordPress plugins.
Affected Version(s)
WP iCal Availability <= 1.0.3
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)