CVE-2023-37869: WordPress Premium Addons PRO plugin <= 2.9.0 - Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in Premium Addons Premium Addons PRO.This issue affects Premium Addons PRO: from n/a through 2.9.0.
Affected Software
3 affected components
Premium Addons Premium Addons PRO<=2.9.0
WordPress Premium Addons PRO<=2.9.0
Leap13 Premium Addons Wordpress<2.9.1
Remediation
Information
Update to 2.9.1 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-37869?
CVE-2023-37869 is classified as a Missing Authorization vulnerability, which can lead to unauthorized access.
2
How do I fix CVE-2023-37869?
To fix CVE-2023-37869, upgrade Premium Addons PRO to version 2.9.1 or later.
3
Which versions of Premium Addons PRO are affected by CVE-2023-37869?
CVE-2023-37869 affects all versions of Premium Addons PRO up to and including 2.9.0.
4
What type of vulnerability is CVE-2023-37869?
CVE-2023-37869 is a Missing Authorization vulnerability that can compromise user permissions.
5
Who is the vendor affected by CVE-2023-37869?
The vendor affected by CVE-2023-37869 is Leap13, specifically their Premium Addons PRO product.