First published: Thu Jun 13 2024(Updated: )
Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pressified SendPress | <=1.23.11.6 | |
SendPress Newsletters | <=1.23.11.6 | |
SendPress Newsletters | <=1.23.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-35040 is considered moderate due to its missing authorization vulnerability.
To fix CVE-2023-35040, you should update the SendPress Newsletters plugin to version 1.23.11.7 or later.
CVE-2023-35040 affects SendPress Newsletters versions from n/a through 1.23.11.6.
CVE-2023-35040 is a missing authorization vulnerability.
As a temporary mitigation for CVE-2023-35040, restrict access to the affected functionalities until an update is applied.