CVE-2023-50882: WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through <= 4.13.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50882?
CVE-2023-50882 is considered a significant vulnerability due to its missing authorization and incorrectly configured access control levels.
How do I fix CVE-2023-50882?
To fix CVE-2023-50882, update ProfilePress to version 4.13.3 or later, which includes the necessary security patch.
What versions of ProfilePress are affected by CVE-2023-50882?
CVE-2023-50882 affects ProfilePress versions up to and including 4.13.2.
What are the risks of not addressing CVE-2023-50882?
Not addressing CVE-2023-50882 may lead to unauthorized access to sensitive user information due to inadequate access controls.
Is user data at risk due to CVE-2023-50882?
Yes, user data can be at risk if CVE-2023-50882 is exploited, allowing attackers to bypass authorization mechanisms.