CVE-2023-1874: WP Data Access <= 5.3.7 - Authenticated (Subscriber+) Privilege Escalation
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiplerolesupdate function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wpdarole[]' parameter during a profile update. This requires the 'Enable role management' setting to be enabled for the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1874?
CVE-2023-1874 is classified as a medium severity vulnerability, posing a risk of privilege escalation.
How do I fix CVE-2023-1874?
To mitigate CVE-2023-1874, update the WP Data Access plugin to version 5.3.8 or later.
Who is affected by CVE-2023-1874?
CVE-2023-1874 affects users of the WP Data Access plugin for WordPress in versions up to 5.3.7.
What causes the vulnerability in CVE-2023-1874?
CVE-2023-1874 is caused by a lack of proper authorization checks in the multiple_roles_update function.
Can unprivileged users exploit CVE-2023-1874?
Yes, authenticated users with minimal permissions, such as subscribers, can exploit CVE-2023-1874.