PT-2024-12997 · WordPress · Click To Tweet

Thiennv

·

Published

2024-12-13

·

Updated

2024-12-17

·

CVE-2023-41857

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Click To Tweet versions through 2.0.14
Description The issue affects the Click To Tweet plugin, allowing exploitation of incorrectly configured access control security levels due to a missing authorization vulnerability. This results in broken access control. The estimated number of potentially affected devices is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For versions through 2.0.14, update to the latest version to mitigate risks and ensure security. As a temporary workaround, consider restricting access to vulnerable components of the Click To Tweet plugin until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-41857

Affected Products

Click To Tweet