PT-2024-12869 · WordPress · Radio Player

Alex Thomas

·

Published

2024-08-17

·

Updated

2024-08-28

·

CVE-2023-4025

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Radio Player plugin for WordPress versions up to, and including, 2.0.73
Description The issue is related to a missing capability check on the update player function, allowing unauthenticated attackers to update player instances. This enables unauthorized modification of data.
Recommendations For versions up to, and including, 2.0.73, consider disabling the update player function until a patch is available to prevent unauthorized data modification. Restrict access to the update functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-4025

Affected Products

Radio Player