SB2023060216 - Improper Authorization in Nested Pages plugin for WordPress
Published: June 2, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authorization (CVE-ID: CVE-2023-2434)
The vulnerability allows a remote user to bypass the authorization mechanisms.
The vulnerability exists due to a missing capability check on the "reset" function. A remote administrator can bypass access restrictions and reset plugin settings.
Remediation
Install update from vendor's website.
References
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2919175%40wp-nested-pages&old=2814681%40wp-nested-pages&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/8c3e61e9-3610-41b5-9820-28012dc657fd?source=cve
- https://plugins.trac.wordpress.org/browser/wp-nested-pages/tags/3.2.3/app/Form/Listeners/ResetSettings.php#L12