CVE-2023-22697: WordPress Survey Maker plugin <= 3.2.0 - Broken Access Control vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through <= 3.2.0.
Affected Software
3 affected components
Survey Maker Survey Maker<=3.2.0
WordPress Survey Maker<=3.2.0
ays-pro Survey Maker Wordpress<3.2.1
Remediation
Information
Update the WordPress Survey Maker plugin to the latest available version (at least 3.2.1).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-22697?
CVE-2023-22697 is classified as a high-severity vulnerability due to its potential for exploitation through missing authorization.
2
How do I fix CVE-2023-22697?
To fix CVE-2023-22697, update the Survey Maker plugin to the latest version that addresses the access control issues.
3
What versions are affected by CVE-2023-22697?
CVE-2023-22697 affects Survey Maker versions up to and including 3.2.0.
4
What is the nature of the flaw in CVE-2023-22697?
CVE-2023-22697 involves missing authorization due to incorrectly configured access control security levels.
5
Who is impacted by CVE-2023-22697?
Users of Survey Maker or WordPress Survey Maker versions up to 3.2.0 are impacted by CVE-2023-22697.