CVE-2023-23976: WordPress RegistrationMagic plugin <= 5.1.9.2 - Arbitrary Price Change
Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23976?
CVE-2023-23976 is classified as a vulnerability with incorrect default permissions that may allow unauthorized access to certain functionalities.
How do I fix CVE-2023-23976?
To fix CVE-2023-23976, update Metagauss RegistrationMagic to the latest version that addresses the permissions issue.
Which versions of RegistrationMagic are affected by CVE-2023-23976?
CVE-2023-23976 affects all versions of Metagauss RegistrationMagic from n/a up to and including 5.1.9.2.
What type of vulnerability is CVE-2023-23976?
CVE-2023-23976 is an incorrect default permissions vulnerability related to access control lists (ACLs).
Can CVE-2023-23976 lead to unauthorized access?
Yes, CVE-2023-23976 can potentially allow unauthorized users to access functionalities not properly constrained by ACLs.