CVE-2023-26523: WordPress Calculated Fields Form plugin <= 1.1.120 - Missing Authorization Leading To Feedback Submission Vulnerability
Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects Calculated Fields Form: from n/a through 1.1.120.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26523?
CVE-2023-26523 is a high-severity vulnerability due to its missing authorization that allows functionality misuse in the CodePeople Calculated Fields Form.
How do I fix CVE-2023-26523?
To fix CVE-2023-26523, update the CodePeople Calculated Fields Form plugin to the latest version beyond 1.1.120, ensuring that proper authorization measures are in place.
What specific software versions are affected by CVE-2023-26523?
CVE-2023-26523 affects both CodePeople Calculated Fields Form and WordPress Calculated Fields Form versions up to and including 1.1.120.
What type of attacks can CVE-2023-26523 lead to?
CVE-2023-26523 can lead to functionality misuse, which may allow unauthorized feedback submissions on affected forms.
Is there a workaround for CVE-2023-26523 if I can't update immediately?
A temporary workaround for CVE-2023-26523 involves disabling the affected plugin until an update can be applied to mitigate the risks.