CVE-2023-44472: WordPress Unyson plugin <= 2.7.28 - Broken Access Control vulnerability
Published May 3, 2024
·Updated
Missing Authorization vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.28.
Affected Software
3 affected components
ThemeFuse Unyson<=2.7.28
WordPress Unyson<=2.7.28
Brizy Unyson Wordpress<=2.7.28
Event History
May 3, 2024
CVE Published
via MITRE·07:33 AM
Data Sourced
via MITRE·07:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-44472?
CVE-2023-44472 is considered a critical missing authorization vulnerability affecting Unyson versions up to 2.7.28.
2
How do I fix CVE-2023-44472?
To fix CVE-2023-44472, update the Unyson plugin to the latest version where the vulnerability has been patched.
3
What systems are affected by CVE-2023-44472?
CVE-2023-44472 affects the ThemeFuse Unyson plugin as well as its integration with WordPress versions up to 2.7.28.
4
Can CVE-2023-44472 lead to data breaches?
Yes, CVE-2023-44472 can potentially allow attackers to gain unauthorized access to sensitive data.
5
Is there a workaround for CVE-2023-44472?
Currently, the best solution for CVE-2023-44472 is to update to a patched version of the Unyson plugin.