CVE-2023-2833: ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rxsetscreenoptions' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wpscreenoptions[option]' and 'wpscreenoptions[value]' parameters during a screen option update.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2833?
CVE-2023-2833 is a vulnerability in the ReviewX plugin for WordPress that allows authenticated attackers with minimal permissions to escalate their privileges.
How severe is CVE-2023-2833?
CVE-2023-2833 has a severity rating of 8.8, which is considered high.
What is the affected software by CVE-2023-2833?
The affected software by CVE-2023-2833 is the ReviewX plugin for WordPress up to and including version 1.6.13.
How can an attacker exploit CVE-2023-2833?
An attacker can exploit CVE-2023-2833 by using the 'rx_set_screen_options' function in the ReviewX plugin to escalate their privileges.
Is there a fix for CVE-2023-2833?
Yes, updating the ReviewX plugin to a version beyond 1.6.13 will fix CVE-2023-2833.