CVE-2023-2434
Severity
3.8LOW
EPSS
0.1%
top 84.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 31
Description
The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:LExploitability: 1.2 | Impact: 2.5
Affected Packages2 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-3mwx-cqmc-fxfr: The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions↗2023-05-31
CVEList▶
Nested Pages <= 3.2.3 - Missing Authorization to Authenticated (Editor+) Plugin Settings Reset↗2023-05-31