CVE-2023-5454: Templately < 2.2.6 - Arbitrary post trashing via Missing Authorization
Published Nov 6, 2023
·Updated
The Templately WordPress plugin before 2.2.6 does not properly authorize the saved-templates/delete REST API call, allowing unauthenticated users to delete arbitrary posts.
Affected Software
1 affected component
Templately Templately WordPress<2.2.6
Event History
Nov 6, 2023
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-5454?
CVE-2023-5454 is a vulnerability in the Templately WordPress plugin that allows unauthenticated users to delete arbitrary posts.
2
How severe is CVE-2023-5454?
CVE-2023-5454 has a severity score of 7.5, which is considered high.
3
How does CVE-2023-5454 affect Templately plugin?
CVE-2023-5454 affects Templately plugin versions prior to 2.2.6, allowing unauthenticated users to delete arbitrary posts via the `saved-templates/delete` REST API call.
4
Can the vulnerability be exploited without authentication?
Yes, CVE-2023-5454 can be exploited by unauthenticated users.
5
Is there a fix available for CVE-2023-5454?
Yes, the fix for CVE-2023-5454 is to upgrade Templately plugin to version 2.2.6 or newer.