First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople CP Multi View Event Calendar | <=1.4.13 | |
Dwbooster Calendar Event Multi View | <=1.4.13 |
Update the WordPress CP Multi View Event Calendar plugin to the latest available version (at least 1.4.15).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-23814 is considered significant due to the potential for unauthorized access to sensitive data.
To fix CVE-2023-23814, update CodePeople CP Multi View Event Calendar to version 1.4.14 or later to address the missing authorization vulnerability.
CVE-2023-23814 affects CodePeople CP Multi View Event Calendar versions up to and including 1.4.13.
CVE-2023-23814 is a missing authorization vulnerability that allows exploitation of incorrectly configured access control security levels.
Yes, CVE-2023-23814 can potentially expose user data by allowing unauthorized access if not mitigated.