First published: Sat Aug 12 2023(Updated: )
The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'profile[role]' parameter during a profile update.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager Premium Packages | <=5.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4293 has been classified as a privilege escalation vulnerability.
To fix CVE-2023-4293, update the Premium Packages - Sell Digital Products Securely plugin to version 5.7.5 or later.
CVE-2023-4293 affects users of the Premium Packages - Sell Digital Products Securely plugin for WordPress versions up to and including 5.7.4.
Yes, authenticated attackers with minimal permissions can exploit CVE-2023-4293 due to insufficient restrictions on the affected function.
CVE-2023-4293 compromises the security of the 'wpdmpp_update_profile' function, allowing privilege escalation.