PT-2023-17387 · WordPress · Web Stories For Wordpress

Swissspidy

·

Published

2023-05-08

·

Updated

2023-11-01

·

CVE-2023-1979

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Web Stories for WordPress versions prior to 1.32
Description The Web Stories for WordPress plugin has a vulnerability that allows users with the "Author" role to bypass permission checks and access password-protected content. Normally, users with this role cannot edit password-protected stories, but the vulnerability enables them to duplicate protected stories in the plugin's dashboard, giving them access to the content.
Recommendations For versions prior to 1.32, upgrade to version 1.32 or beyond to resolve the issue. As a temporary workaround, consider restricting access to the plugin's dashboard for users with the "Author" role until the update is applied.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-1979

Affected Products

Web Stories For Wordpress