CVE-2023-52230: WordPress Booster Plus for WooCommerce plugin < 7.1.3 - Authenticated Arbitrary WordPress Option Disclosure Vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.3.
Affected Software
1 affected component
Booster Booster for WooCommerce WordPress<=7.1.3
Remediation
Information
Update to 7.1.3 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·09:08 AM
Data Sourced
via MITRE·09:08 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-52230?
CVE-2023-52230 is classified as a medium severity vulnerability due to the potential for unauthorized access to sensitive information.
2
How do I fix CVE-2023-52230?
To fix CVE-2023-52230, upgrade Booster Plus for WooCommerce to version 7.1.4 or later.
3
What type of vulnerability is CVE-2023-52230?
CVE-2023-52230 is a Missing Authorization vulnerability that could allow unauthorized users to access restricted functionality.
4
Which versions of Booster Plus for WooCommerce are affected by CVE-2023-52230?
Booster Plus for WooCommerce versions prior to 7.1.3 are affected by CVE-2023-52230.
5
Is user authentication required to exploit CVE-2023-52230?
No, CVE-2023-52230 can potentially be exploited by users who do not have proper authorization.