CVE-2023-47682: WordPress WP User Frontend plugin <= 3.6.5 - Authenticated Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.
Affected Software
2 affected components
weDevs WP User Frontend<=3.6.5
WordPress WP User Frontend<=3.6.5
Remediation
Information
Update to 3.6.6 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47682?
CVE-2023-47682 is categorized as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2023-47682?
To fix CVE-2023-47682, update the WP User Frontend plugin to the latest version beyond 3.6.5.
3
What impact does CVE-2023-47682 have on affected systems?
CVE-2023-47682 allows unauthorized users to escalate their privileges on the affected WordPress sites.
4
Which versions of WP User Frontend are affected by CVE-2023-47682?
CVE-2023-47682 affects all versions of WP User Frontend from n/a up to and including version 3.6.5.
5
Who is the vendor responsible for CVE-2023-47682?
The vendor responsible for CVE-2023-47682 is weDevs, which develops the WP User Frontend plugin.