CVE-2023-23975: WordPress Quick Event Manager plugin <= 9.7.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in brightvesseldev Quick Event Manager quick-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through <= 9.7.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23975?
CVE-2023-23975 is classified as a Missing Authorization vulnerability that can lead to potential unauthorized access.
How do I fix CVE-2023-23975?
To fix CVE-2023-23975, ensure that proper access control measures are configured and update Fullworks Quick Event Manager to the latest version.
Which versions of Fullworks Quick Event Manager are affected by CVE-2023-23975?
CVE-2023-23975 affects Fullworks Quick Event Manager from version n/a up to and including version 9.7.4.
Can CVE-2023-23975 affect WordPress?
Yes, CVE-2023-23975 also affects the WordPress version of Quick Event Manager up to version 9.7.4.
What type of access controls are inadequate in CVE-2023-23975?
CVE-2023-23975 involves incorrectly configured access control security levels that allow exploitation.