CVE-2023-36684: WordPress Convert Pro plugin <= 1.7.5 - Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5.
Affected Software
1 affected component
Brainstormforce Convert Pro Wordpress<1.7.6
Remediation
Information
Update to 1.7.6 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-36684?
CVE-2023-36684 has been classified as a critical vulnerability due to the missing authorization issue allowing unauthorized access.
2
How do I fix CVE-2023-36684?
To fix CVE-2023-36684, update the Convert Pro plugin to version 1.7.6 or later immediately.
3
What versions are affected by CVE-2023-36684?
CVE-2023-36684 affects all versions of Convert Pro from n/a up to and including 1.7.5.
4
What potential impact could CVE-2023-36684 have on my site?
CVE-2023-36684 could allow attackers to bypass access controls, potentially compromising sensitive information.
5
Is there a known workaround for CVE-2023-36684?
There are no official workarounds for CVE-2023-36684; updating the plugin is the recommended solution.