CVE-2023-47807: WordPress 10WebAnalytics plugin <= 1.2.12 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in 10Web 10WebAnalytics wd-google-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAnalytics: from n/a through <= 1.2.12.
Affected Software
3 affected components
10web 10WebAnalytics<=1.2.12
WordPress 10WebAnalytics<=1.2.12
10web 10webanalytics Wordpress<=1.2.12
Event History
Jan 2, 2025
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47807?
CVE-2023-47807 is classified as a missing authorization vulnerability affecting 10WebAnalytics.
2
How do I fix CVE-2023-47807?
To fix CVE-2023-47807, update 10WebAnalytics to version 1.2.13 or later to ensure proper access control.
3
What versions of 10WebAnalytics are affected by CVE-2023-47807?
CVE-2023-47807 affects all versions of 10WebAnalytics up to and including 1.2.12.
4
What type of vulnerability is CVE-2023-47807?
CVE-2023-47807 is a missing authorization vulnerability that allows exploiting incorrectly configured access control security levels.
5
Who is impacted by CVE-2023-47807?
Users of 10WebAnalytics and WordPress installations utilizing versions up to 1.2.12 are impacted by CVE-2023-47807.