CVE-2023-32798: WordPress Simple Page Ordering plugin <= 2.5.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in 10up Simple Page Ordering simple-page-ordering allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Page Ordering: from n/a through <= 2.5.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32798?
The severity of CVE-2023-32798 is considered high due to the missing authorization vulnerabilities that allow unauthorized access.
How do I fix CVE-2023-32798?
To fix CVE-2023-32798, update the Simple Page Ordering plugin to version 2.5.1 or later to address the access control issues.
What versions are affected by CVE-2023-32798?
CVE-2023-32798 affects Simple Page Ordering plugin versions from n/a up to and including 2.5.0.
What types of vulnerabilities does CVE-2023-32798 involve?
CVE-2023-32798 involves a missing authorization vulnerability leading to improper access controls.
Who is the vendor of the software affected by CVE-2023-32798?
The vendor of the affected software is 10up, which developed the Simple Page Ordering plugin.