CVE-2023-50904: WordPress Poll Maker plugin <= 4.8.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through <= 4.8.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50904?
CVE-2023-50904 is a medium severity vulnerability due to missing authorization which allows attackers to exploit incorrectly configured access control security levels.
How do I fix CVE-2023-50904?
To fix CVE-2023-50904, ensure that access control settings are correctly configured and update to the latest version of Poll Maker or the WordPress Poll Maker plugin.
What software versions are affected by CVE-2023-50904?
CVE-2023-50904 affects Poll Maker versions up to and including 4.8.0 and the WordPress Poll Maker plugin versions up to and including 4.8.0.
What type of vulnerability is CVE-2023-50904?
CVE-2023-50904 is classified as a missing authorization vulnerability that can lead to unauthorized access and exploitation.
Who is responsible for the vulnerability described in CVE-2023-50904?
The vulnerability is present in Poll Maker products, specifically versions of Poll Maker and the WordPress Poll Maker plugin prior to version 4.8.0.