First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Meta slider and carousel with lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta slider and carousel with lightbox: from n/a through 1.6.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
MetaSlider | <=1.6.2 | |
MetaSlider WordPress Slider, Gallery, and Carousel | <=1.6.2 |
Update the WordPress Meta slider and carousel with lightbox plugin to the latest available version (at least 1.7).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25703 has been classified as a missing authorization vulnerability which poses a high risk due to improperly configured access controls.
To fix CVE-2023-25703, update the Meta slider and carousel with lightbox plugin to the latest version beyond 1.6.2.
CVE-2023-25703 affects versions of the Meta slider and carousel with lightbox up to and including 1.6.2.
CVE-2023-25703 can be exploited to gain unauthorized access, allowing attackers to manipulate or retrieve sensitive data.
Users and administrators of the Meta slider and carousel with lightbox plugin version 1.6.2 or earlier are affected by CVE-2023-25703.