PT-2024-12729 · WordPress · Wordpress Qr Code Mecard/Vcard Generator Plugin

Abdi Pranata

·

Published

2024-12-13

·

Updated

2024-12-17

·

CVE-2023-38477

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress QR Code MeCard/VCard Generator Plugin versions 1.5.6 through 1.6.0
Description A high-severity issue affects the QR code MeCard/vCard generator, allowing broken access control due to missing authorization. This issue can be exploited due to incorrectly configured access control security levels. Remediation is crucial to secure sites using the affected plugin.
Recommendations For versions 1.5.6 through 1.6.0, update to the latest version to secure your site. At the moment, there is no information about other mitigation measures for this issue.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-38477

Affected Products

Wordpress Qr Code Mecard/Vcard Generator Plugin