CVE-2023-2078
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jul 11, 2023
Updated: Nov 7, 2023
Summary
CVE-2023-2078 is a vulnerability affecting the "Buy Me a Coffee – Button and Widget Plugin" for WordPress. This issue allows authenticated attackers, even with minimal permissions like subscribers, to modify plugin settings without proper capability checks on functions such as receive_post, bmc_disconnect, name_post, and widget_post. Versions up to and including 3.7 are susceptible to this unauthorized data manipulation. No confirmation has been made if CVE-2023-25030 is a duplicate of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.