CVE-2023-47191: WordPress Youzify Plugin <= 1.2.2 is vulnerable to Insecure Direct Object References (IDOR)
Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47191?
CVE-2023-47191 is classified as a critical vulnerability due to its potential for unauthorized access.
How do I fix CVE-2023-47191?
To fix CVE-2023-47191, update the Youzify plugin for WordPress to version 1.2.4 or later.
Which software is affected by CVE-2023-47191?
CVE-2023-47191 affects the Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress versions up to 1.2.3.
What type of vulnerability is CVE-2023-47191?
CVE-2023-47191 is an Authorization Bypass Through User-Controlled Key vulnerability.
Who is the vendor for CVE-2023-47191?
The vendor for CVE-2023-47191 is KaineLabs, the developer of the Youzify plugin.