CVE-2023-44142: WordPress Inactive Logout plugin <= 3.2.2 - Broken Access Control vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in Deepen Bajracharya Inactive Logout inactive-logout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Inactive Logout: from n/a through <= 3.2.2.
Affected Software
1 affected component
Deepen Bajracharya Inactive Logout<=3.2.2
Remediation
Information
Update the WordPress Inactive Logout plugin to the latest available version (at least 3.2.3).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-44142?
CVE-2023-44142 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-44142?
To fix CVE-2023-44142, upgrade Inactive Logout to a version beyond 3.2.2.
3
What type of vulnerability is CVE-2023-44142?
CVE-2023-44142 is a missing authorization vulnerability related to access control.
4
Which versions of Inactive Logout are affected by CVE-2023-44142?
CVE-2023-44142 affects Inactive Logout versions up to and including 3.2.2.
5
What can happen if CVE-2023-44142 is exploited?
Exploiting CVE-2023-44142 can allow unauthorized access due to incorrectly configured security levels.