CVE-2023-6048: Estatik Real Estate Plugin < 4.1.1 - Subscriber+ Arbitrary Option Update
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and lead to DoS when certain options are reset
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6048?
CVE-2023-6048 is considered a high-severity vulnerability due to its potential for Denial of Service (DoS) on affected sites.
How do I fix CVE-2023-6048?
To fix CVE-2023-6048, update the Estatik Real Estate Plugin to version 4.1.1 or later.
Who is affected by CVE-2023-6048?
CVE-2023-6048 affects users of the Estatik Real Estate Plugin for WordPress versions prior to 4.1.1.
What impact does CVE-2023-6048 have on WordPress sites?
CVE-2023-6048 allows users with low privileges to alter site settings, potentially leading to site disruptions and a Denial of Service.
What versions of the Estatik plugin are vulnerable to CVE-2023-6048?
All versions of the Estatik Real Estate Plugin prior to 4.1.1 are vulnerable to CVE-2023-6048.