CVE-2023-27437: WordPress Event Espresso 4 Decaf plugin <= 4.10.44.decaf - Bypass vulnerability
Published Jun 3, 2024
·Updated
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.
Affected Software
2 affected components
Event Espresso Event Espresso 4 Decaf<=4.10.44.decaf
WordPress Event Espresso 4 Decaf<=4.10.44.decaf
Remediation
Information
Update to 4.10.45.decaf or a higher version.
Event History
Jun 3, 2024
CVE Published
via MITRE·09:59 PM
Data Sourced
via MITRE·09:59 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-27437?
CVE-2023-27437 is classified as a Missing Authorization vulnerability that allows for functionality misuse.
2
How do I fix CVE-2023-27437?
To fix CVE-2023-27437, upgrade to Event Espresso 4 Decaf version 4.10.45 or later.
3
What products are affected by CVE-2023-27437?
CVE-2023-27437 affects Event Espresso 4 Decaf versions up to and including 4.10.44.
4
What type of vulnerability is CVE-2023-27437?
CVE-2023-27437 is a Missing Authorization vulnerability allowing unauthorized functionality misuse.
5
Can CVE-2023-27437 be exploited remotely?
Yes, CVE-2023-27437 can potentially be exploited remotely, impacting users of the affected software.