CVE-2023-45766: WordPress Poll Maker plugin <= 4.7.1 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through <= 4.7.1.
Affected Software
3 affected components
Poll Maker Poll Maker<=4.7.1
WordPress Poll Maker<=4.7.1
ays-pro Poll Maker Wordpress<4.7.2
Remediation
Information
Update the WordPress Poll Maker plugin to the latest available version (at least 4.7.2).
Event History
Jan 2, 2025
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45766?
CVE-2023-45766 has a medium severity rating due to its potential for unauthorized access.
2
How do I fix CVE-2023-45766?
To fix CVE-2023-45766, update Poll Maker to the latest version beyond 4.7.1 which addresses the access control issue.
3
What types of systems are affected by CVE-2023-45766?
CVE-2023-45766 affects Poll Maker versions up to 4.7.1, including the WordPress Poll Maker plugin.
4
What is the nature of the vulnerability in CVE-2023-45766?
CVE-2023-45766 is a Missing Authorization vulnerability that allows for exploitation through incorrectly configured access control.
5
Is there a patch available for CVE-2023-45766?
Yes, a patch is available in the latest version of Poll Maker after 4.7.1 to address CVE-2023-45766.