CVE-2023-49156: WordPress GoDaddy Email Marketing plugin <= 1.4.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in GoDaddy GoDaddy Email Marketing godaddy-email-marketing-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GoDaddy Email Marketing: from n/a through <= 1.4.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49156?
CVE-2023-49156 is classified as a critical vulnerability due to its potential impact on data confidentiality and unauthorized access.
How do I fix CVE-2023-49156?
To mitigate CVE-2023-49156, upgrade GoDaddy Email Marketing to version 1.4.4 or later to ensure proper access controls are enforced.
Which versions of GoDaddy Email Marketing are affected by CVE-2023-49156?
CVE-2023-49156 affects GoDaddy Email Marketing versions from n/a through 1.4.3.
What type of vulnerability is CVE-2023-49156?
CVE-2023-49156 is a Missing Authorization vulnerability related to incorrectly configured access control security levels.
Does CVE-2023-49156 affect the GoDaddy Email Marketing plugin for WordPress?
Yes, CVE-2023-49156 also affects the GoDaddy Email Marketing plugin for WordPress versions up to 1.4.3.