The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).
History

Thu, 06 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-03-06T15:14:23.559Z

Reserved: 2023-01-16T18:56:21.114Z

Link: CVE-2023-0328

cve-icon Vulnrichment

Updated: 2024-08-02T05:10:55.585Z

cve-icon NVD

Status : Modified

Published: 2023-03-06T14:15:10.573

Modified: 2025-03-06T16:15:39.403

Link: CVE-2023-0328

cve-icon Redhat

No data.