CVE-2023-46079

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 862

Summary

CVE-2023-46079 is a critical vulnerability affecting the WP Royal Ashe Extra plugin. The issue resides in the plugin's authorization mechanism, allowing unauthorized access due to incorrectly configured access control security levels. As a result, attackers can exploit this missing authorization vulnerability, gaining privileged access to affected installations. This security flaw poses a significant risk, particularly for sites using Ashe Extra versions 1.2.9 and below. Organizations using this plugin are strongly advised to update to the latest version and implement robust access control policies to minimize risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share