CVE-2023-41796: WordPress Sunshine Photo Cart Plugin < 3.0.0 is vulnerable to Insecure Direct Object References (IDOR)
Published Dec 20, 2023
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0.
Affected Software
1 affected component
sunshinephotocart Sunshine Photo Cart Wordpress<3.0
Remediation
Information
Update to 3.0.0 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-41796?
CVE-2023-41796 is classified as a high-severity vulnerability due to the potential for unauthorized access.
2
How do I fix CVE-2023-41796?
To fix CVE-2023-41796, update the Sunshine Photo Cart plugin to version 3.0.0 or later.
3
What systems are affected by CVE-2023-41796?
CVE-2023-41796 affects all versions of Sunshine Photo Cart for WordPress below version 3.0.0.
4
What type of vulnerability is CVE-2023-41796?
CVE-2023-41796 is an Authorization Bypass Through User-Controlled Key vulnerability.
5
Is CVE-2023-41796 actively exploited in the wild?
There have been no public reports indicating that CVE-2023-41796 is actively exploited, but it is advisable to apply patches promptly.