PT-2024-15147 · WordPress · The Pods – Custom Content Types/Fields

Nex Team

·

Published

2024-04-09

·

Updated

2025-01-22

·

CVE-2023-6965

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Pods – Custom Content Types and Fields plugin for WordPress versions prior to 3.0.11, excluding versions 2.7.31.2, 2.8.23.2, and 2.9.19.2.
Description The issue is related to Missing Authorization, which allows authenticated attackers with contributor access or higher to create pods and users with default role. This is possible due to a file inclusion feature via shortcode.
Recommendations For versions prior to 3.0.11, excluding versions 2.7.31.2, 2.8.23.2, and 2.9.19.2, update to version 3.0.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the file inclusion feature via shortcode to minimize the risk of exploitation. Restrict contributor access or higher to prevent attackers from creating pods and users with default role.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-6965

Affected Products

The Pods – Custom Content Types/Fields