PT-2023-8830 · WordPress · Podlove Web Player

Published

2023-11-09

·

Updated

2024-03-20

·

CVE-2023-47691

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Podlove Web Player versions through 5.7.3
Description The issue is related to insufficient authorization procedures in the Podlove Web Player plugin for WordPress, allowing a remote attacker to impact the integrity and confidentiality of protected information.
Recommendations For versions through 5.7.3, update to a version that includes a fix for the authorization issue, as the current version may allow unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-02115
CVE-2023-47691

Affected Products

Podlove Web Player