CVE-2023-41865: WordPress Slider Pro plugin <= 4.8.6 - Broken Access Control vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in bqworks Slider Pro sliderpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Pro: from n/a through <= 4.8.6.
Affected Software
1 affected component
Bqworks Slider Pro<=4.8.6
Remediation
Information
Update the WordPress Slider Pro plugin to the latest available version (at least 4.8.7).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-41865?
CVE-2023-41865 is classified as a medium severity vulnerability due to missing authorization in Slider Pro.
2
How do I fix CVE-2023-41865?
To fix CVE-2023-41865, update Slider Pro to version 4.8.7 or later, which addresses the access control issues.
3
What software is affected by CVE-2023-41865?
CVE-2023-41865 affects bqworks Slider Pro versions up to and including 4.8.6.
4
What type of vulnerability is CVE-2023-41865?
CVE-2023-41865 is a missing authorization vulnerability that can exploit incorrectly configured access control security levels.
5
Can CVE-2023-41865 be exploited remotely?
Yes, CVE-2023-41865 can be exploited remotely if attackers can access the affected components of Slider Pro.