CVE-2023-2623: KiviCare Management System < 3.2.1 - Subscriber+ Sensitive Information Disclosure
The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-2623.
What is the severity of CVE-2023-2623?
The severity of CVE-2023-2623 is medium with a CVSS score of 6.5.
What is the description of CVE-2023-2623?
CVE-2023-2623 is a vulnerability in the KiviCare WordPress plugin before version 3.2.1 that allows low privilege users to retrieve sensitive information of other users such as email and hashed passwords.
How does CVE-2023-2623 impact KiviCare WordPress plugin?
CVE-2023-2623 allows low privilege users to access and retrieve sensitive user information from the KiviCare WordPress plugin.
How can I fix CVE-2023-2623?
To fix CVE-2023-2623, it is recommended to update the KiviCare WordPress plugin to version 3.2.1 or newer.