← Back

CVE-2023-0551

nvd nist
Published: Aug 16, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments

Affected (1)

1 product
Rest Api To Miniprogram
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.6.1

References (2)

Timeline

No history available yet.