PT-2024-13437 · WordPress · Ladiapp

Giongfnef

·

Published

2024-08-17

·

Updated

2024-08-19

·

CVE-2023-4730

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions LadiApp plugin for WordPress versions up to and including 4.3
Description The issue allows unauthorized modification of data due to a missing capability check on the init endpoint() function. This enables unauthenticated attackers to modify various settings, including the ladipage key, which can be used to create new posts on the website and inject malicious web scripts.
Recommendations For versions up to and including 4.3, update to a version that includes a fix for the missing capability check on the init endpoint() function. As a temporary workaround, consider disabling the init endpoint() function until a patch is available. Restrict access to the ladipage key setting to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-4730

Affected Products

Ladiapp