Missing Authorization in LuckyWP Scripts Control by LuckyWP
CVE-2023-47778

4.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
2 January 2025

Summary

A Missing Authorization vulnerability exists in the LuckyWP Scripts Control, which may allow unauthorized users to exploit access controls that are not correctly configured. This issue primarily affects versions of LuckyWP Scripts Control up to and including 1.2.1, posing significant security risks to websites utilizing this plugin. Properly implemented access control mechanisms are essential to prevent unauthorized actions by threat actors, and failure to secure these controls can result in severe breaches and data exposure.

Affected Version(s)

LuckyWP Scripts Control <= 1.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.