CVE-2023-49812: WordPress WP Photo Album Plus Plugin <= 8.5.02.005 is vulnerable to Insecure Direct Object References (IDOR)
Published Dec 19, 2023
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
Affected Software
1 affected component
Wppa Wp Photo Album Plus Wordpress<=8.5.02.005
Event History
Dec 19, 2023
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49812?
CVE-2023-49812 has been classified as a medium severity vulnerability due to its potential to bypass authorization controls.
2
How do I fix CVE-2023-49812?
To fix CVE-2023-49812, update the WP Photo Album Plus plugin to the latest version beyond 8.5.02.005.
3
What specific issue does CVE-2023-49812 cause?
CVE-2023-49812 allows for an authorization bypass through user-controlled keys, potentially exposing sensitive data.
4
Which versions of WP Photo Album Plus are affected by CVE-2023-49812?
CVE-2023-49812 affects all versions of WP Photo Album Plus up to and including 8.5.02.005.
5
Is CVE-2023-49812 related to insecure direct object references?
Yes, CVE-2023-49812 is associated with insecure direct object references, leading to potential unauthorized access.