CVE-2023-33321: WordPress EventPrime plugin <= 2.8.6 - Sensitive Data Exposure
Published May 17, 2024
·Updated
Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.
Affected Software
3 affected components
Metagauss Eventprime Wordpress<3.0.0
Metagauss EventPrime>undefined
WordPress EventPrime<=2.8.6
Remediation
Information
Update to 3.0.0 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·06:45 AM
Data Sourced
via MITRE·06:45 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-33321?
CVE-2023-33321 is considered a medium severity vulnerability due to its potential for unauthorized access caused by missing authorization in Metagauss EventPrime.
2
How do I fix CVE-2023-33321?
To fix CVE-2023-33321, update Metagauss EventPrime to version 3.0.0 or later to ensure proper access control configurations.
3
What versions of Metagauss EventPrime are affected by CVE-2023-33321?
CVE-2023-33321 affects versions of Metagauss EventPrime from n/a through 2.8.6.
4
What type of vulnerability is CVE-2023-33321?
CVE-2023-33321 is classified as a Missing Authorization vulnerability.
5
Can CVE-2023-33321 impact WordPress installations?
Yes, CVE-2023-33321 can impact WordPress installations using the Metagauss EventPrime plugin in versions up to 2.8.6.