CVE-2023-6327: ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products
The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchasednewproducts function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6327?
CVE-2023-6327 is considered a high severity vulnerability due to its potential for unauthorized data access.
How do I fix CVE-2023-6327?
To fix CVE-2023-6327, update the ShopLentor plugin to version 2.8.8 or later.
Who is affected by CVE-2023-6327?
CVE-2023-6327 affects all versions of the ShopLentor plugin for WordPress up to and including 2.8.7.
What type of vulnerability is CVE-2023-6327?
CVE-2023-6327 is a vulnerability that allows unauthorized access to data due to a missing capability check.
Can unauthenticated attackers exploit CVE-2023-6327?
Yes, unauthenticated attackers can exploit CVE-2023-6327 to view sensitive data.