First published: Sat May 20 2023(Updated: )
The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_license' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the license key and support license key, but it can only be changed to a valid license key.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
barnraiser AROUNDMe | <=2.7.9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2714 is a vulnerability in the Groundhogg plugin for WordPress that allows authenticated attackers to modify data without proper authorization.
Versions up to and including 2.7.9.8 of the Groundhogg plugin for WordPress are affected by CVE-2023-2714.
CVE-2023-2714 has a severity rating of medium (4.3).
Authenticated attackers with subscriber-level permissions and above can exploit CVE-2023-2714 to modify data without proper authorization.
Yes, the Groundhogg plugin has released a fix in version 2.7.10 to address the vulnerability CVE-2023-2714.