First published: Fri Dec 13 2024(Updated: )
Missing Authorization vulnerability in weDevs WP Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through 2.6.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Project Manager by WeDevs | <2.6.8 | |
WP Project Manager | <=2.6.7 | |
WP Project Manager | <=2.6.7 |
No patched version is available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40003 is classified as a high severity vulnerability due to its potential for exploitation through missing authorization.
To fix CVE-2023-40003, upgrade WP Project Manager to version 2.6.8 or later.
CVE-2023-40003 is caused by incorrectly configured access control security levels within the WP Project Manager plugin.
WP Project Manager versions from n/a through 2.6.7 are affected by CVE-2023-40003.
Yes, CVE-2023-40003 can lead to unauthorized access due to its missing authorization vulnerability.