Missing Authorization Vulnerability in WP iCal Availability Plugin
CVE-2023-46607

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
2 January 2025

Summary

A missing authorization vulnerability in the WP iCal Availability plugin allows attackers to exploit incorrectly configured access control security levels. This issue permits unauthorized users to access functions intended for authenticated users, potentially leading to unauthorized information disclosure or manipulation. The affected versions include WP iCal Availability up to 1.0.3, emphasizing the need for security measures in WordPress plugins.

Affected Version(s)

WP iCal Availability <= 1.0.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.