CVE-2023-47805: WordPress WPCafe plugin <= 2.2.22 - Broken Access Control vulnerability
Published Dec 9, 2024
·Updated
Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 2.2.22.
Affected Software
3 affected components
Themewinter WPCafe<=2.2.22
WordPress WPCafe<=2.2.22
Themewinter Wpcafe Wordpress<2.2.23
Remediation
Information
No patched version is available.
Event History
Dec 9, 2024
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47805?
The severity of CVE-2023-47805 is rated as high due to its potential impact on security through missing authorization controls.
2
How do I fix CVE-2023-47805?
To fix CVE-2023-47805, update your Themewinter WPCafe plugin to version 2.2.23 or later.
3
What systems are affected by CVE-2023-47805?
CVE-2023-47805 affects Themewinter WPCafe versions up to 2.2.22.
4
What type of vulnerability is CVE-2023-47805?
CVE-2023-47805 is classified as a missing authorization vulnerability that results from incorrectly configured access control security levels.
5
Can CVE-2023-47805 be exploited remotely?
Yes, CVE-2023-47805 can be exploited remotely without authentication, making it a significant risk.