PT-2024-14923 · WordPress · Woostify Sites Library
Krzysztof Zając
·
Published
2024-01-29
·
Updated
2026-02-20
·
CVE-2023-6279
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Woostify Sites Library WordPress plugin versions prior to 1.4.8
Description
The issue concerns a lack of authorization in an AJAX action, allowing any authenticated users to update arbitrary blog options and set them to 'activated'. This could potentially lead to a Denial of Service (DoS) when using a specific option name.
Recommendations
For versions prior to 1.4.8, update to version 1.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action to prevent unauthorized updates to blog options.
Exploit
Fix
DoS
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woostify Sites Library