PT-2024-15123 · WordPress · Acurax

István Márton

·

Published

2024-02-28

·

Updated

2024-02-28

·

CVE-2023-6922

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Acurax plugin for WordPress versions up to, and including, 2.6
Description The issue allows authenticated attackers to extract sensitive data, such as names and email addresses of subscribed visitors, due to Sensitive Information Exposure. This is possible via the acx csma subscribe ajax function.
Recommendations For Acurax plugin for WordPress versions up to, and including, 2.6, consider disabling the acx csma subscribe ajax function until a patch is available to prevent exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-6922

Affected Products

Acurax