CVE-2023-7019: LightStart – Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 - Missing Authorization
The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the inserttemplate function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to change page designs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7019?
CVE-2023-7019 is considered a medium severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2023-7019?
To fix CVE-2023-7019, update the LightStart plugin to version 2.6.9 or later, which addresses the missing capability check.
What versions of the LightStart plugin are affected by CVE-2023-7019?
CVE-2023-7019 affects all versions of the LightStart plugin up to and including version 2.6.8.
What type of attack does CVE-2023-7019 enable?
CVE-2023-7019 enables authenticated users to perform unauthorized modification of data.
Who is the vendor for the LightStart plugin related to CVE-2023-7019?
The vendor for the LightStart plugin associated with CVE-2023-7019 is Themeisle.