CVE-2023-23645: WordPress MainWP Code Snippets Extension Plugin <= 4.0.2 - Subscriber+ Arbitrary PHP Code Injection/Execution Vulnerability
Published May 17, 2024
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2.
Affected Software
3 affected components
MainWP Code Snippets Extension<=4.0.2
WordPress MainWP Code Snippets Extension Plugin<=4.0.2
MainWP Code Snippets Extension Wordpress<4.0.3
Remediation
Information
Update to 4.0.3 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·06:30 AM
Data Sourced
via MITRE·06:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23645?
CVE-2023-23645 is classified as a high severity vulnerability due to its potential for code injection.
2
How do I fix CVE-2023-23645?
To fix CVE-2023-23645, update the MainWP Code Snippets Extension to the latest version beyond 4.0.2.
3
What are the potential impacts of CVE-2023-23645?
The potential impacts of CVE-2023-23645 include unauthorized code execution and complete system compromise.
4
Which versions of the MainWP Code Snippets Extension are affected by CVE-2023-23645?
CVE-2023-23645 affects all versions of the MainWP Code Snippets Extension prior to and including version 4.0.2.
5
Is the WordPress MainWP Code Snippets Extension Plugin affected by CVE-2023-23645?
Yes, the WordPress MainWP Code Snippets Extension Plugin is affected by CVE-2023-23645 up to version 4.0.2.