CVE-2023-48774: WordPress IdeaPush plugin < 8.58 - Broken Access Control vulnerability
Published Dec 9, 2024
·Updated
Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through < 8.58.
Affected Software
3 affected components
Martin Gibson IdeaPush<8.58
WordPress IdeaPush<8.58
Northernbeacheswebsites Ideapush Wordpress<8.58
Remediation
Information
No patched version is available. No reply from the vendor.
Event History
Dec 9, 2024
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-48774?
CVE-2023-48774 is classified as a Missing Authorization vulnerability affecting IdeaPush.
2
How do I fix CVE-2023-48774?
To fix CVE-2023-48774, ensure that access control security levels are correctly configured within the IdeaPush plugin.
3
Which versions of IdeaPush are affected by CVE-2023-48774?
CVE-2023-48774 affects all versions of IdeaPush up to and including 8.58.
4
What type of vulnerability is CVE-2023-48774?
CVE-2023-48774 is a Missing Authorization vulnerability, leading to improperly configured access controls.
5
Who is the vendor for the software affected by CVE-2023-48774?
The vendor for the affected software is Martin Gibson, specifically for their IdeaPush product.