CVE-2023-6798

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 6, 2024
Updated: Jan 12, 2024
CWE ID 862

Summary

The vulnerability with CVE ID CVE-2023-6798 affects the RSS Aggregator by Feedzy plugin for WordPress, specifically versions up to and including 4.3.2. This vulnerability allows authenticated attackers with author-level access or above to change the plugin's settings, including proxy settings. The danger lies in the fact that these unauthorized changes can be made without a capability check. To remediate this vulnerability, users should update their plugin to a version beyond 4.3.2 that addresses this issue. This vulnerability poses a medium risk with a base score of 5.4 and an impact score of 2.5 according to NIST's National Vulnerability Database (NVD).

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-6798 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options