CVE-2023-52176: WordPress Malware Scanner plugin <= 4.7.1 - IP Restriction Bypass vulnerability
Published Jun 4, 2024
·Updated
Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.
Affected Software
2 affected components
miniOrange Malware Scanner>=n/a<4.7.1
WordPress Malware Scanner<=4.7.1
Remediation
Information
Update to 4.7.2 or a higher version.
Event History
Jun 4, 2024
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-52176?
CVE-2023-52176 is classified as a high severity vulnerability due to its potential to allow unauthorized access.
2
How do I fix CVE-2023-52176?
To fix CVE-2023-52176, update the miniorange Malware Scanner plugin to the latest version or version 4.7.2 or later.
3
What versions of miniorange Malware Scanner are affected by CVE-2023-52176?
CVE-2023-52176 affects miniorange Malware Scanner versions from n/a through 4.7.1.
4
What kind of vulnerability is CVE-2023-52176?
CVE-2023-52176 is an authentication bypass by spoofing vulnerability.
5
What functionality is impacted by CVE-2023-52176?
CVE-2023-52176 allows accessing functionality not properly constrained by access control lists (ACLs).