CVE-2023-23976Incorrect Default Permissions in Registrationmagic

Severity
7.5HIGHNVD
EPSS
0.1%
top 77.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 24

Description

Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5metagauss/registrationmagicn/a5.1.9.2

🔴Vulnerability Details

2
CVEList
WordPress RegistrationMagic plugin <= 5.1.9.2 - Arbitrary Price Change2024-04-24
GHSA
GHSA-4qj3-r8v4-x3fg: Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs2024-04-24
CVE-2023-23976 — Incorrect Default Permissions | cvebase