CVE-2023-36681: WordPress Cryptocurrency Widgets – Price Ticker & Coins List plugin <= 2.6.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in CoolHappy Cryptocurrency Widgets – Price Ticker & Coins List cryptocurrency-price-ticker-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through <= 2.6.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36681?
CVE-2023-36681 is categorized as a missing authorization vulnerability that can lead to unauthorized access due to incorrectly configured access control.
How do I fix CVE-2023-36681?
To fix CVE-2023-36681, upgrade Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List to version 2.6.3 or later.
What are the risks associated with CVE-2023-36681?
Exploiting CVE-2023-36681 may allow attackers to gain unauthorized access to sensitive features or data within the affected plugin.
Which versions of Cryptocurrency Widgets are affected by CVE-2023-36681?
CVE-2023-36681 affects all versions of Cryptocurrency Widgets – Price Ticker & Coins List up to and including version 2.6.2.
Who is the vendor for the products affected by CVE-2023-36681?
The vendor for the affected products is Cool Plugins, specifically their Cryptocurrency Widgets – Price Ticker & Coins List plugin.