Missing Authorization in KaizenCoders Short URL Plugin by WordPress
CVE-2023-47225
5.4MEDIUM
Summary
The KaizenCoders Short URL plugin for WordPress is susceptible to a missing authorization vulnerability, which allows an attacker to exploit incorrectly configured access control security levels. This can result in unauthorized actions that compromise the integrity and confidentiality of the application. Users are encouraged to update to a secure version promptly to mitigate these risks.
Affected Version(s)
Short URL <= 1.6.8
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)