CVE-2023-47764: WordPress Ditty plugin <= 3.1.24 - Broken Access Control vulnerability
Missing Authorization vulnerability in metaphorcreations Ditty ditty-news-ticker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ditty: from n/a through <= 3.1.24.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47764?
CVE-2023-47764 is classified as a missing authorization vulnerability that can lead to improper access control.
How do I fix CVE-2023-47764?
To fix CVE-2023-47764, ensure that proper access controls are configured correctly on Metaphor Creations Ditty versions up to 3.1.24.
Which versions of Ditty are affected by CVE-2023-47764?
CVE-2023-47764 affects Metaphor Creations Ditty versions from unknown to 3.1.24.
What types of attacks can CVE-2023-47764 enable?
CVE-2023-47764 can enable unauthorized access to user data and functionalities due to incorrect access control configurations.
Is the WordPress Ditty plugin vulnerable to CVE-2023-47764?
Yes, the WordPress Ditty plugin is also vulnerable to CVE-2023-47764 for versions up to 3.1.24.