CVE-2023-48757: WordPress JetEngine plugin <= 3.2.4 - Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.
Affected Software
2 affected components
Crocoblock JetEngine<=3.2.4
WordPress JetEngine<=3.2.4
Remediation
Information
Update to 3.2.5 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:38 AM
Data Sourced
via MITRE·08:38 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-48757?
CVE-2023-48757 is classified as a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2023-48757?
To fix CVE-2023-48757, update Crocoblock JetEngine to the latest version available beyond 3.2.4.
3
What systems are affected by CVE-2023-48757?
CVE-2023-48757 affects Crocoblock JetEngine and WordPress JetEngine versions up to and including 3.2.4.
4
What type of vulnerability is CVE-2023-48757?
CVE-2023-48757 is an improper privilege management vulnerability that allows for privilege escalation.
5
What impact does CVE-2023-48757 have?
CVE-2023-48757 could allow an attacker to escalate their privileges within the affected JetEngine application.