PT-2023-32064 · WordPress · Awesome Support

Krzysztof Zając

·

Published

2023-11-06

·

Updated

2023-11-14

·

CVE-2023-5352

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Awesome Support WordPress plugin versions prior to 6.1.5
Description The issue allows users to edit posts for which they do not have permission due to incorrect authorization of the wpas edit reply function.
Recommendations For versions prior to 6.1.5, update to version 6.1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the wpas edit reply function until a patch is available.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-5352

Affected Products

Awesome Support