CVE-2023-6279

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 29, 2024
Updated: Feb 3, 2024
CWE ID 862

Summary

CVE-2023-6279 is a vulnerability affecting the Woostify Sites Library WordPress plugin prior to version 1.4.8. This issue grants authenticated users, including subscribers, unauthorized access to update arbitrary blog options. By setting a specific option to 'activated', attackers can cause a Denial of Service (DoS) attack, exploiting this security flaw.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share