CVE-2023-6491: Strong Testimonials <= 3.1.12 - Authenticated(Contributor+) Improper Authorization to Views Modification
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtstsaveviewsticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify favorite views.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6491?
CVE-2023-6491 has a medium severity rating due to the potential for unauthorized data modification.
How do I fix CVE-2023-6491?
To fix CVE-2023-6491, update the Strong Testimonials plugin to version 3.1.13 or later.
Who is affected by CVE-2023-6491?
CVE-2023-6491 affects all versions of the Strong Testimonials plugin for WordPress up to and including 3.1.12.
What type of vulnerability is CVE-2023-6491?
CVE-2023-6491 is a vulnerability that allows unauthorized modification of data due to improper capability checks.
Can authenticated users exploit CVE-2023-6491?
Yes, authenticated users with contributor roles can potentially exploit CVE-2023-6491 to modify data.