First published: Tue Oct 31 2023(Updated: )
The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
<2.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5098 is a vulnerability in the Campaign Monitor Forms by Optin Cat WordPress plugin before version 2.5.6 that allows users with low privileges to overwrite options on a site.
CVE-2023-5098 allows users with low privileges to overwrite options in the plugin, potentially leading to a variety of outcomes, including denial-of-service (DoS).
CVE-2023-5098 has a severity rating of 8.1 (high).
To fix CVE-2023-5098, update the Campaign Monitor Forms by Optin Cat plugin to version 2.5.6 or later.
You can find more information about CVE-2023-5098 at the following reference: [https://wpscan.com/vulnerability/3167a83c-291e-4372-a42e-d842205ba722]