CVE-2023-46311: WordPress wpDiscuz Plugin <= 7.6.3 is vulnerable to Insecure Direct Object References (IDOR)
Published Dec 20, 2023
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3.
Affected Software
1 affected component
gVectors Wpdiscuz Wordpress<7.6.4
Remediation
Information
Update to 7.6.4 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46311?
CVE-2023-46311 has been rated as a high severity vulnerability due to its capability for authorization bypass.
2
How do I fix CVE-2023-46311?
To fix CVE-2023-46311, update the wpDiscuz plugin to version 7.6.4 or later.
3
Who is affected by CVE-2023-46311?
CVE-2023-46311 affects all versions of wpDiscuz prior to 7.6.4.
4
What kind of vulnerability is CVE-2023-46311?
CVE-2023-46311 is an authorization bypass vulnerability that allows unauthorized access to features.
5
Can CVE-2023-46311 be exploited remotely?
Yes, CVE-2023-46311 can be exploited remotely by an attacker to gain unauthorized access.