CVE-2023-46628

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 862

Summary

CVE-2023-46628 is a new vulnerability affecting the WP Word Count plugin used with RedLettuce. This Missing Authorization issue arises due to incorrectly configured access control security levels, allowing unauthorized access. The plugin versions from n/a through 3.2.4 are impacted. Successful exploitation could lead to potential data manipulation or unauthorized actions. Users are advised to update their plugin to the latest version with proper access control settings.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share