CVE-2023-41953: WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability
Published Dec 9, 2024
·Updated
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.
Affected Software
3 affected components
ProfilePress ProfilePress>n/a, <=4.13.1
WordPress ProfilePress plugin<=4.13.1
properfraction Profilepress Wordpress<4.13.2
Remediation
Information
Update the WordPress ProfilePress plugin to the latest available version (at least 4.13.2).
Event History
Dec 9, 2024
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-41953?
CVE-2023-41953 is classified as a Missing Authorization vulnerability.
2
How do I fix CVE-2023-41953?
To fix CVE-2023-41953, update ProfilePress to version 4.13.2 or later.
3
What versions of ProfilePress are affected by CVE-2023-41953?
CVE-2023-41953 affects ProfilePress versions from n/a to 4.13.1.
4
Can CVE-2023-41953 lead to unauthorized access?
Yes, CVE-2023-41953 can potentially allow unauthorized access due to lacking proper authorization controls.
5
Is there a patch available for CVE-2023-41953?
Yes, a patch is available in the updated versions of ProfilePress post 4.13.1.