CVE-2023-51692: WordPress Customer Reviews for WooCommerce Plugin <= 5.38.1 is vulnerable to Broken Access Control
Published Feb 28, 2024
·Updated
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.
Affected Software
3 affected components
CusRev Customer Reviews For Woocommerce Wordpress<5.38.2
CusRev Customer Reviews for WooCommerce<=5.38.1
WordPress Customer Reviews for WooCommerce Plugin<=5.38.1
Remediation
Information
Update to 5.38.2 or a higher version.
Event History
Feb 28, 2024
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51692?
CVE-2023-51692 is classified as a Missing Authorization vulnerability which can lead to unauthorized access.
2
How do I fix CVE-2023-51692?
To fix CVE-2023-51692, upgrade the CusRev Customer Reviews for WooCommerce plugin to version 5.38.2 or later.
3
What versions of the CusRev Customer Reviews for WooCommerce are affected by CVE-2023-51692?
CVE-2023-51692 affects all versions of the CusRev Customer Reviews for WooCommerce plugin up to and including 5.38.1.
4
What type of vulnerability is CVE-2023-51692?
CVE-2023-51692 is a Missing Authorization vulnerability that allows unauthorized users to potentially access restricted functionalities.
5
Who is the vendor of the affected CusRev Customer Reviews for WooCommerce plugin in CVE-2023-51692?
The vendor of the affected plugin in CVE-2023-51692 is CusRev.