CVE-2023-33923: Broken Access Control leading to Arbitrary Plugin Activation in multiple HashThemes themes
Published Mar 25, 2024
·Updated
Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Viral News: from n/a through 1.4.5; Viral: from n/a through 1.8.0; HashOne: from n/a through 1.3.0.
Affected Software
3 affected components
HashThemes Viral News<=1.4.5
HashThemes Viral<=1.8.0
HashThemes HashOne<=1.3.0
Event History
Mar 25, 2024
CVE Published
via MITRE·04:46 AM
Data Sourced
via MITRE·04:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-33923?
CVE-2023-33923 has a medium severity due to the missing authorization vulnerability in multiple HashThemes products.
2
How do I fix CVE-2023-33923?
To fix CVE-2023-33923, you should update HashThemes Viral News to version 1.4.6 or later, Viral to 1.8.1 or later, and HashOne to 1.3.1 or later.
3
Which versions of HashThemes are affected by CVE-2023-33923?
CVE-2023-33923 affects HashThemes Viral News up to version 1.4.5, Viral up to version 1.8.0, and HashOne up to version 1.3.0.
4
Who is the vendor for CVE-2023-33923?
The vendor for CVE-2023-33923 is HashThemes.
5
What products are impacted by CVE-2023-33923?
The impacted products by CVE-2023-33923 include HashThemes Viral News, Viral, and HashOne.