CVE-2023-35052: WordPress Directorist plugin <= 7.5.4 - Arbitrary Content Deletion vulnerability
Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 7.5.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35052?
CVE-2023-35052 is categorized as a missing authorization vulnerability, which can lead to unauthorized access and exploitation.
How do I fix CVE-2023-35052?
To fix CVE-2023-35052, update the WP Business Directory Plugin and Classified Listings Directory Directorist to a version above 7.5.4.
What versions are affected by CVE-2023-35052?
CVE-2023-35052 affects Directorist versions from n/a up to and including 7.5.4.
What impact does CVE-2023-35052 have on users?
CVE-2023-35052 allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions.
Is there a workaround for CVE-2023-35052?
Currently, the recommended action for CVE-2023-35052 is to update the plugin, as no specific workaround has been provided.