CVE-2023-32295: WordPress Easy!Appointments plugin <= 1.3.3 - Arbitrary File Deletion vulnerability
Published Apr 11, 2024
·Updated
Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.
Affected Software
3 affected components
Alex Tselegidis Easy!Appointments>=1.3.3
WordPress Easy!Appointments<=1.3.3
EasyAppointments Easy\!appointments Wordpress<1.4.0
Remediation
Information
Update to 1.4.0 or a higher version.
Event History
Apr 11, 2024
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-32295?
CVE-2023-32295 is classified as a Missing Authorization vulnerability.
2
How do I fix CVE-2023-32295?
To mitigate CVE-2023-32295, you should update Easy!Appointments to the latest version beyond 1.3.3.
3
What versions are affected by CVE-2023-32295?
CVE-2023-32295 affects Easy!Appointments versions from n/a through 1.3.3.
4
Who is the vendor for CVE-2023-32295?
The vendor for CVE-2023-32295 is Alex Tselegidis.
5
Is CVE-2023-32295 also relevant for WordPress users?
Yes, CVE-2023-32295 impacts the WordPress version of Easy!Appointments up to 1.3.3.