CVE-2023-46628
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 2, 2025
CWE ID 862
Summary
CVE-2023-46628 is a new vulnerability affecting the WP Word Count plugin used with RedLettuce. This Missing Authorization issue arises due to incorrectly configured access control security levels, allowing unauthorized access. The plugin versions from n/a through 3.2.4 are impacted. Successful exploitation could lead to potential data manipulation or unauthorized actions. Users are advised to update their plugin to the latest version with proper access control settings.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.