CVE-2023-7288: Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'update_profile_preference'
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the updateprofilepreference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change plugin settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7288?
CVE-2023-7288 has a medium severity rating due to potential unauthorized data modifications.
How do I fix CVE-2023-7288?
To fix CVE-2023-7288, update the Paytium: Mollie payment forms & donations plugin to version 4.4.0 or later.
Who is affected by CVE-2023-7288?
Users of the Paytium: Mollie payment forms & donations plugin for WordPress, up to version 4.3.7, are affected by CVE-2023-7288.
What type of vulnerability is CVE-2023-7288?
CVE-2023-7288 is a vulnerability that allows unauthorized data modification due to a missing capability check.
Can CVE-2023-7288 be exploited remotely?
Yes, CVE-2023-7288 can be exploited by authenticated attackers who can leverage the missing capability check.