CVE-2023-48758: WordPress JetEngine plugin <= 3.2.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.2.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48758?
CVE-2023-48758 is classified as a missing authorization vulnerability, which can lead to unauthorized access if exploited.
How do I fix CVE-2023-48758?
To fix CVE-2023-48758, update Crocoblock JetEngine to the latest version beyond 3.2.4 where the vulnerability has been patched.
Who is affected by CVE-2023-48758?
CVE-2023-48758 affects users of Crocoblock JetEngine and WordPress JetEngine versions up to and including 3.2.4.
What type of vulnerability is CVE-2023-48758?
CVE-2023-48758 is a missing authorization vulnerability that can exploit incorrectly configured access control security levels.
Can CVE-2023-48758 be exploited easily?
The exploitation of CVE-2023-48758 depends on the configuration of access controls, making it potentially easy for attackers with improper configurations.