CVE-2023-28990: WordPress Viral Mag theme <= 1.0.9 - Authenticated Arbitrary Plugin Activation Vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in hashthemes Viral Mag viral-mag allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Mag: from n/a through <= 1.0.9.
Affected Software
1 affected component
HashThemes Viral Mag<=1.0.9
Remediation
Information
Update the WordPress Viral Mag theme to the latest available version (at least 1.1.0).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28990?
CVE-2023-28990 is classified as a critical vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2023-28990?
To fix CVE-2023-28990, update the HashThemes Viral Mag theme to the latest version beyond 1.0.9.
3
What type of vulnerability is CVE-2023-28990?
CVE-2023-28990 is a Missing Authorization vulnerability that allows exploiting incorrectly configured access control.
4
Which versions of Viral Mag are affected by CVE-2023-28990?
CVE-2023-28990 affects HashThemes Viral Mag versions from n/a to 1.0.9 inclusive.
5
What impact does CVE-2023-28990 have on users?
CVE-2023-28990 can allow attackers to gain unauthorized access to sensitive features and functionalities of the Viral Mag theme.