PT-2023-27196 · WordPress · The Waiting

Marco Wotschka

·

Published

2023-08-31

·

Updated

2023-09-01

·

CVE-2023-3999

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Waiting: One-click countdowns plugin for WordPress versions up to, and including, 0.6.2
Description The issue is related to authorization bypass due to missing capability checks on AJAX calls. This allows authenticated attackers with subscriber-level permissions and above to create and delete countdowns, as well as manipulate other plugin settings.
Recommendations For versions up to, and including, 0.6.2, update to a version that includes the necessary capability checks on AJAX calls to prevent authorization bypass.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-3999

Affected Products

The Waiting