CVE-2023-47756: WordPress Welcome Email Editor plugin <= 5.0.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in David Vongries Welcome Email Editor welcome-email-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcome Email Editor: from n/a through <= 5.0.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47756?
CVE-2023-47756 has been identified as a Missing Authorization vulnerability that allows unauthorized access to features in the Welcome Email Editor.
How do I fix CVE-2023-47756?
To fix CVE-2023-47756, update the Welcome Email Editor to version 5.0.6 or later to address the access control security issues.
What versions are affected by CVE-2023-47756?
CVE-2023-47756 affects all versions of the Welcome Email Editor up to and including 5.0.6.
What impact does CVE-2023-47756 have on my site?
CVE-2023-47756 can allow attackers to exploit improperly configured access control settings, potentially leading to unauthorized actions on your website.
Are there any workarounds for CVE-2023-47756?
As a workaround for CVE-2023-47756, you can disable the Welcome Email Editor plugin until you can update to a secure version.