CVE-2023-4027: Radio Player <= 2.0.73 - Missing Authorization to Settings Update
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updatesettings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update plugin settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4027?
CVE-2023-4027 has a medium severity rating due to its potential for unauthorized data modification.
How do I fix CVE-2023-4027?
To fix CVE-2023-4027, update the Radio Player plugin to version 2.0.74 or later.
Who is affected by CVE-2023-4027?
Users of the Radio Player plugin for WordPress versions up to and including 2.0.73 are affected by CVE-2023-4027.
What kind of attacks can exploit CVE-2023-4027?
CVE-2023-4027 can be exploited by unauthenticated attackers to modify plugin settings without authorization.
Is there a known workaround for CVE-2023-4027?
There are no officially recommended workarounds for CVE-2023-4027; updating the plugin is the best solution.