PT-2023-16360 · WordPress · Contentstudio
Marco Wotschka
·
Published
2023-01-27
·
Updated
2026-04-08
·
CVE-2023-0556
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ContentStudio plugin for WordPress versions prior to 1.2.5
Description
The issue is related to authorization bypass due to a missing capability check on several functions. This allows unauthenticated attackers to obtain blog metadata, including the plugin's
contentstudio token, via the cstu get metadata function. Knowing this token enables other interactions with the plugin, such as creating posts.Recommendations
For versions prior to 1.2.5, update to version 1.2.5 or later, which adds other requirements to posting and updating, mitigating the risk of exploitation.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contentstudio