CVE-2023-45765: WordPress WP ERP plugin <= 1.12.6 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.12.6.
Affected Software
3 affected components
weDevs Wp Erp Wordpress<1.12.7
weDevs WP ERP<=1.12.6
WordPress WP ERP<=1.12.6
Remediation
Information
Update the WordPress WP ERP plugin to the latest available version (at least 1.12.7).
Event History
Jan 2, 2025
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45765?
CVE-2023-45765 is classified with a high severity due to its potential to allow unauthorized access.
2
How do I fix CVE-2023-45765?
To fix CVE-2023-45765, update the weDevs WP ERP plugin to version 1.12.7 or higher.
3
What are the affected versions of CVE-2023-45765?
CVE-2023-45765 affects weDevs WP ERP versions up to and including 1.12.6.
4
What type of vulnerability is CVE-2023-45765?
CVE-2023-45765 is a missing authorization vulnerability that exploits incorrectly configured access control.
5
Who is affected by CVE-2023-45765?
Users of weDevs WP ERP versions from n/a through 1.12.6 are affected by CVE-2023-45765.