CVE-2023-38513: WordPress Photo Engine Plugin <= 6.2.5 is vulnerable to Insecure Direct Object References (IDOR)
Published Dec 20, 2023
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engine (Media Organizer & Lightroom): from n/a through 6.2.5.
Affected Software
1 affected component
Meowapps Photo Engine Wordpress<6.2.6
Remediation
Information
Update to 6.2.6 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·01:52 PM
Data Sourced
via MITRE·01:52 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38513?
CVE-2023-38513 has been rated with a high severity due to its potential impact on system security.
2
How do I fix CVE-2023-38513?
To fix CVE-2023-38513, update the Meowapps Photo Engine plugin to version 6.2.6 or later.
3
Which versions of Meowapps Photo Engine are affected by CVE-2023-38513?
CVE-2023-38513 affects all versions of Meowapps Photo Engine from n/a up to 6.2.5.
4
What type of vulnerability is CVE-2023-38513?
CVE-2023-38513 is an Authorization Bypass Through User-Controlled Key vulnerability.
5
Who is affected by CVE-2023-38513?
Users of Meowapps Photo Engine (Media Organizer & Lightroom) who have versions 6.2.5 and earlier are affected by CVE-2023-38513.