The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as well as manipulate other plugin settings.
References
Configurations
History
21 Nov 2024, 08:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/waiting/trunk/waiting.php?rev=2826039 - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/293070c8-783f-404d-9250-392713703ce4?source=cve - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
01 Sep 2023, 13:05
Type | Values Removed | Values Added |
---|---|---|
First Time |
Plugin
Plugin waiting |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
References | (MISC) https://plugins.trac.wordpress.org/browser/waiting/trunk/waiting.php?rev=2826039 - Patch | |
References | (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/293070c8-783f-404d-9250-392713703ce4?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:plugin:waiting:*:*:*:*:*:wordpress:*:* |
31 Aug 2023, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-31 06:15
Updated : 2024-11-21 08:18
NVD link : CVE-2023-3999
Mitre link : CVE-2023-3999
CVE.ORG link : CVE-2023-3999
JSON object : View
Products Affected
plugin
- waiting
CWE
CWE-862
Missing Authorization