CVE-2023-46309: WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.10.
Affected Software
3 affected components
gVectors Team wpDiscuz<=7.6.10
WordPress wpDiscuz<=7.6.10
gVectors Wpdiscuz Wordpress<7.6.11
Remediation
Information
Update the WordPress wpDiscuz plugin to the latest available version (at least 7.6.11).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46309?
CVE-2023-46309 is considered a high severity vulnerability due to the potential for unauthorized access.
2
How do I fix CVE-2023-46309?
To fix CVE-2023-46309, update wpDiscuz to version 7.6.11 or later.
3
What kind of vulnerability is CVE-2023-46309?
CVE-2023-46309 is a Missing Authorization vulnerability that allows exploiting incorrectly configured access control security levels.
4
Which versions of wpDiscuz are affected by CVE-2023-46309?
CVE-2023-46309 affects wpDiscuz versions from n/a up to and including 7.6.10.
5
Can CVE-2023-46309 impact my WordPress site?
Yes, CVE-2023-46309 can impact your WordPress site if you are using an affected version of the wpDiscuz plugin.