CVE-2023-45760: WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.3.
Affected Software
3 affected components
gVectors Team wpDiscuz<=7.6.3
WordPress wpDiscuz<=7.6.3
gVectors Wpdiscuz Wordpress<7.6.4
Remediation
Information
Update the WordPress wpDiscuz plugin to the latest available version (at least 7.6.4).
Event History
Jan 2, 2025
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45760?
CVE-2023-45760 has a high severity rating due to its potential for unauthorized access and exploitation.
2
How do I fix CVE-2023-45760?
To fix CVE-2023-45760, update the wpDiscuz plugin to version 7.6.4 or later, as this addresses the missing authorization vulnerability.
3
Which versions of wpDiscuz are affected by CVE-2023-45760?
CVE-2023-45760 affects wpDiscuz versions up to and including 7.6.3.
4
What types of attacks can CVE-2023-45760 facilitate?
CVE-2023-45760 can facilitate unauthorized access to sensitive features or data due to incorrectly configured access controls.
5
Who is affected by CVE-2023-45760?
Users and administrators using wpDiscuz versions up to 7.6.3 in their WordPress sites are affected by CVE-2023-45760.