CVE-2023-23896: WordPress URL Shortener by MyThemeShop Plugin <= 1.0.17 is vulnerable to Broken Access Control
Published Jan 17, 2024
·Updated
Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17.
Affected Software
1 affected component
MyThemeShop Url Shortener Wordpress<=1.0.17
Event History
Jan 17, 2024
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23896?
CVE-2023-23896 is categorized as a missing authorization vulnerability with potentially significant impact.
2
How do I fix CVE-2023-23896?
To fix CVE-2023-23896, update the MyThemeShop URL Shortener plugin to the latest version beyond 1.0.17.
3
What versions are affected by CVE-2023-23896?
CVE-2023-23896 affects MyThemeShop URL Shortener plugin versions up to and including 1.0.17.
4
What type of vulnerability is CVE-2023-23896?
CVE-2023-23896 is a missing authorization vulnerability that can lead to unauthorized access to resources.
5
Can CVE-2023-23896 be exploited remotely?
Yes, CVE-2023-23896 can be remotely exploited if an attacker can access the vulnerable MyThemeShop URL Shortener plugin.