CVE-2023-47189: WordPress Defender Security plugin <= 4.2.0 - Masked Login Area View Bypass vulnerability
Published Jun 4, 2024
·Updated
Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.2.0.
Affected Software
3 affected components
WPMU DEV Defender Security<=4.2.0
WordPress Defender Security<=4.2.0
wpmudev Defender Wordpress<4.2.1
Remediation
Information
Update to 4.2.1 or a higher version.
Event History
Jun 4, 2024
CVE Published
via MITRE·09:31 AM
Data Sourced
via MITRE·09:31 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47189?
CVE-2023-47189 is classified as a high severity vulnerability due to improper authentication allowing unauthorized access.
2
How do I fix CVE-2023-47189?
To fix CVE-2023-47189, upgrade WPMU DEV Defender Security to version 4.2.1 or later.
3
What functionality is affected by CVE-2023-47189?
CVE-2023-47189 allows accessing functionalities that are not properly constrained by Access Control Lists (ACLs).
4
Which versions of Defender Security are impacted by CVE-2023-47189?
CVE-2023-47189 affects all versions of WPMU DEV Defender Security up to and including version 4.2.0.
5
Is CVE-2023-47189 related to WordPress?
Yes, CVE-2023-47189 affects the Defender Security plugin for WordPress.