CVE-2023-35040: WordPress SendPress Newsletters plugin <= 1.26.1.20 - Broken Access Control vulnerability
Published Jun 13, 2024
·Updated
Missing Authorization vulnerability in brewlabs SendPress Newsletters sendpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SendPress Newsletters: from n/a through <= 1.26.1.20.
Affected Software
3 affected components
Pressified Sendpress Wordpress<=1.23.11.6
SendPress SendPress Newsletters<=1.23.11.6
WordPress SendPress Newsletters<=1.23.11.6
Event History
Jun 13, 2024
CVE Published
via MITRE·11:51 PM
Data Sourced
via MITRE·11:51 PM
DescriptionSeverityWeakness
Jun 14, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-35040?
The severity of CVE-2023-35040 is considered moderate due to its missing authorization vulnerability.
2
How do I fix CVE-2023-35040?
To fix CVE-2023-35040, you should update the SendPress Newsletters plugin to version 1.23.11.7 or later.
3
What versions of SendPress Newsletters are affected by CVE-2023-35040?
CVE-2023-35040 affects SendPress Newsletters versions from n/a through 1.23.11.6.
4
What type of vulnerability is CVE-2023-35040?
CVE-2023-35040 is a missing authorization vulnerability.
5
Is there a way to mitigate CVE-2023-35040 before applying the fix?
As a temporary mitigation for CVE-2023-35040, restrict access to the affected functionalities until an update is applied.