CVE-2023-30873: WordPress WP Docs plugin <= 1.9.8 - Broken Access Control
Published Dec 9, 2024
·Updated
Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through <= 1.9.8.
Affected Software
3 affected components
Fahad Mahmood WP Docs<=1.9.8
WordPress WP Docs<=1.9.8
Androidbubble Wp Docs Wordpress<1.9.9
Remediation
Information
Update the WordPress WP Docs plugin to the latest available version (at least 1.9.9).
Event History
Dec 9, 2024
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-30873?
CVE-2023-30873 has been identified as a missing authorization vulnerability affecting WP Docs versions up to 1.9.8.
2
How do I fix CVE-2023-30873?
To fix CVE-2023-30873, update WP Docs to version 1.9.9 or later.
3
What can attackers do with CVE-2023-30873?
Attackers can exploit CVE-2023-30873 to gain unauthorized access to documents due to incorrectly configured access control settings.
4
Who is affected by CVE-2023-30873?
CVE-2023-30873 affects all users of the WP Docs plugin on WordPress versions up to 1.9.8.
5
What should I do if I cannot update my WP Docs plugin due to compatibility issues regarding CVE-2023-30873?
If an update is not feasible, review and adjust the plugin's access control settings to minimize exposure to CVE-2023-30873.