PT-2024-13002 · WordPress · Wp Accessibility Helper

Thiennv

·

Published

2024-12-13

·

Updated

2024-12-17

·

CVE-2023-41869

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Accessibility Helper (WAH) versions 0.6.2 through 0.6.2.4
Description A Missing Authorization vulnerability in WP Accessibility Helper (WAH) allows for exploiting incorrectly configured access control security levels, leading to broken access control. Remediation is crucial to secure WordPress sites.
Recommendations Update to the latest version to secure your WordPress site. As a temporary workaround, consider restricting access to vulnerable components of the WP Accessibility Helper plugin until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-41869

Affected Products

Wp Accessibility Helper