PT-2024-14923 · WordPress · Woostify Sites Library

Krzysztof Zając

·

Published

2024-01-29

·

Updated

2026-02-20

·

CVE-2023-6279

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Woostify Sites Library WordPress plugin versions prior to 1.4.8
Description The issue concerns a lack of authorization in an AJAX action, allowing any authenticated users to update arbitrary blog options and set them to 'activated'. This could potentially lead to a Denial of Service (DoS) when using a specific option name.
Recommendations For versions prior to 1.4.8, update to version 1.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action to prevent unauthorized updates to blog options.

Exploit

Fix

DoS

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-6279

Affected Products

Woostify Sites Library