CVE-2023-41954: WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
Affected Software
3 affected components
ProfilePress ProfilePress<=4.13.1
WordPress ProfilePress<=4.13.1
properfraction Profilepress Wordpress<4.13.2
Event History
May 17, 2024
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-41954?
CVE-2023-41954 is classified as a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2023-41954?
To fix CVE-2023-41954, update your ProfilePress plugin to version 4.13.2 or later.
3
Who is affected by CVE-2023-41954?
CVE-2023-41954 affects all versions of ProfilePress up to and including 4.13.1.
4
What type of vulnerability is CVE-2023-41954?
CVE-2023-41954 is categorized as an Improper Privilege Management vulnerability.
5
How does CVE-2023-41954 impact users?
CVE-2023-41954 allows unauthorized users to escalate their privileges within the application.