Missing Authorization in WP CTA PRO Plugin by WordPress
CVE-2023-46644

6.5MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
2 January 2025

What is CVE-2023-46644?

A missing authorization vulnerability affects the WP CTA PRO plugin for WordPress, allowing improper access control configurations. This oversight could permit attackers to exploit incorrectly set security levels, potentially leading to unauthorized access and exposure of sensitive data. The vulnerability impacts versions from n/a through 1.5.8, emphasizing the need for users to review their plugin configurations and update to secure versions to safeguard their WordPress installations.

Affected Version(s)

WordPress CTA <= 1.5.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.
CVE-2023-46644 : Missing Authorization in WP CTA PRO Plugin by WordPress