CVE-2023-45271: WordPress ProductX – Gutenberg WooCommerce Blocks plugin <= 2.7.8 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in WPXPO WowStore product-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowStore: from n/a through <= 2.7.8.
Affected Software
1 affected component
wpxpo ProductX – Gutenberg WooCommerce Blocks<=2.7.8
Remediation
Information
Update the WordPress ProductX – Gutenberg WooCommerce Blocks plugin to the latest available version (at least 3.0.0).
Event History
Jan 2, 2025
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-45271?
The severity of CVE-2023-45271 is medium with a CVSS score of 4.3.
2
How do I fix CVE-2023-45271?
To fix CVE-2023-45271, update the WordPress ProductX – Gutenberg WooCommerce Blocks plugin to version 3.0.0 or newer.
3
What type of vulnerability is CVE-2023-45271?
CVE-2023-45271 is classified as a Broken Access Control vulnerability.
4
Which versions of the plugin are affected by CVE-2023-45271?
CVE-2023-45271 affects the WPXPO WowStore product-blocks plugin versions from n/a through 2.7.8.
5
What is the potential impact of exploiting CVE-2023-45271?
Exploiting CVE-2023-45271 could allow unauthorized access due to incorrectly configured access control security levels.