CVE-2023-49154: WordPress Button Generator – easily Button Builder plugin <= 2.3.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in Wow-Company Button Generator – easily Button Builder button-generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Button Generator – easily Button Builder: from n/a through <= 2.3.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49154?
CVE-2023-49154 is classified as a missing authorization vulnerability with a high potential impact.
How do I fix CVE-2023-49154?
To fix CVE-2023-49154, update the Wow-Company Button Generator – easily Button Builder to version 2.3.9 or later.
What versions of Wow-Company Button Generator – easily Button Builder are affected by CVE-2023-49154?
Versions from n/a up to 2.3.8 of the Wow-Company Button Generator – easily Button Builder are affected by CVE-2023-49154.
Is the WordPress Button Generator – easily Button Builder also affected by CVE-2023-49154?
Yes, the WordPress Button Generator – easily Button Builder versions from n/a up to 2.3.8 are also affected by CVE-2023-49154.
What is the nature of the vulnerability described in CVE-2023-49154?
CVE-2023-49154 is a missing authorization vulnerability that can be exploited due to incorrectly configured access control security levels.