CVE-2023-2434

Severity
3.8LOW
EPSS
0.1%
top 84.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 31

Description

The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:LExploitability: 1.2 | Impact: 2.5

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3mwx-cqmc-fxfr: The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions2023-05-31
CVEList
Nested Pages <= 3.2.3 - Missing Authorization to Authenticated (Editor+) Plugin Settings Reset2023-05-31
CVE-2023-2434 (LOW CVSS 3.8) | The Nested Pages plugin for WordPre | cvebase.io