CVE-2023-3998: wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a post.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this wpDiscuz plugin vulnerability?
The vulnerability ID for this wpDiscuz plugin vulnerability is CVE-2023-3998.
What is the severity of CVE-2023-3998?
The severity of CVE-2023-3998 is medium with a CVSS score of 5.3.
What is the description of CVE-2023-3998?
CVE-2023-3998 is a vulnerability in the wpDiscuz plugin for WordPress which allows unauthorized modification of data by unauthenticated attackers.
Which versions of wpDiscuz plugin for WordPress are affected by CVE-2023-3998?
Versions up to and including 7.6.3 of the wpDiscuz plugin for WordPress are affected by CVE-2023-3998.
How can the wpDiscuz plugin vulnerability be fixed?
To fix the wpDiscuz plugin vulnerability, users should update to version 7.6.4 or later.