CVE-2023-51672: WordPress FunnelKit Checkout plugin <= 3.10.3 - Unauthenticated Arbitrary Post/Page Deletion vulnerability
Published Mar 21, 2024
·Updated
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
Affected Software
1 affected component
FunnelKit FunnelKit Checkout<=3.10.3
Remediation
Information
Update to 3.11.0 or a higher version.
Event History
Mar 21, 2024
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
RemedyDescriptionSeverityWeakness
Apr 11, 2024
Data Sourced
via NVD·01:22 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-51672?
CVE-2023-51672 has a medium severity rating due to its potential for unauthorized access and control.
2
How do I fix CVE-2023-51672?
To fix CVE-2023-51672, upgrade FunnelKit Checkout to version 3.10.4 or later.
3
What does CVE-2023-51672 affect?
CVE-2023-51672 affects FunnelKit Checkout versions up to and including 3.10.3.
4
What kind of vulnerability is CVE-2023-51672?
CVE-2023-51672 is a missing authorization vulnerability that could allow unauthorized actions.
5
Can CVE-2023-51672 lead to data loss?
Yes, CVE-2023-51672 can lead to data loss through unauthorized arbitrary post or page deletion.