CVE-2023-52232: WordPress Booster Plus for WooCommerce plugin < 7.1.2 - Authenticated Arbitrary Post/Page Deletion Vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.
Affected Software
1 affected component
Booster Booster for WooCommerce WordPress<7.1.2
Remediation
Information
Update to 7.1.2 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·09:06 AM
Data Sourced
via MITRE·09:06 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-52232?
CVE-2023-52232 is considered a critical missing authorization vulnerability that can lead to unauthorized manipulation of posts in Booster Plus for WooCommerce.
2
How do I fix CVE-2023-52232?
To mitigate CVE-2023-52232, upgrade Booster Plus for WooCommerce to version 7.1.2 or later.
3
What versions are affected by CVE-2023-52232?
CVE-2023-52232 affects Booster Plus for WooCommerce versions prior to 7.1.2.
4
Who is impacted by CVE-2023-52232?
Users of Booster Plus for WooCommerce versions before 7.1.2 are vulnerable to CVE-2023-52232.
5
What types of attacks are possible with CVE-2023-52232?
CVE-2023-52232 allows attackers to perform unauthorized actions such as deleting posts or pages if exploited.