CVE-2023-37967: WordPress DirectoryPress plugin <= 3.6.2 - Unauthenticated Broken Access Control Vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.2.
Affected Software
3 affected components
Designinvento DirectoryPress<=3.6.2
WordPress DirectoryPress<=3.6.2
Designinvento Directorypress Wordpress<3.6.4
Remediation
Information
Update the WordPress DirectoryPress plugin to the latest available version (at least 3.6.3).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37967?
CVE-2023-37967 is considered to be a critical security vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2023-37967?
To fix CVE-2023-37967, update Designinvento DirectoryPress to version 3.6.3 or later.
3
What type of vulnerability is CVE-2023-37967?
CVE-2023-37967 is a Missing Authorization vulnerability that results from incorrectly configured access controls.
4
Which versions of DirectoryPress are affected by CVE-2023-37967?
CVE-2023-37967 affects DirectoryPress versions from n/a through 3.6.2.
5
Who is the vendor responsible for CVE-2023-37967?
The vendor responsible for CVE-2023-37967 is Designinvento.