CVE-2023-30486: WordPress Square theme <= 2.0.0 - Broken Access Control
Published Dec 9, 2024
·Updated
Missing Authorization vulnerability in hashthemes Square square allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Square: from n/a through <= 2.0.0.
Affected Software
1 affected component
HashThemes Square (WordPress theme)<=2.0.0
Remediation
Information
Update the WordPress Square theme to the latest available version (at least 2.0.1).
Event History
Dec 9, 2024
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-30486?
CVE-2023-30486 is classified as a missing authorization vulnerability which can lead to unauthorized access.
2
How do I fix CVE-2023-30486?
To fix CVE-2023-30486, update HashThemes Square to version 2.0.1 or later to ensure proper access control.
3
Which versions are affected by CVE-2023-30486?
CVE-2023-30486 affects HashThemes Square versions up to and including 2.0.0.
4
What types of access can be exploited through CVE-2023-30486?
CVE-2023-30486 allows exploitation of incorrectly configured access control security levels.
5
Is CVE-2023-30486 specific to a certain platform?
Yes, CVE-2023-30486 impacts the HashThemes Square theme and its implementations within WordPress.