cve/2023/CVE-2023-0405.md
2024-05-28 08:49:17 +00:00

18 lines
915 B
Markdown

### [CVE-2023-0405](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0405)
![](https://img.shields.io/static/v1?label=Product&message=GPT%20AI%20Power%3A%20Content%20Writer%20%26%20ChatGPT%20%26%20Image%20Generator%20%26%20WooCommerce%20Product%20Writer%20%26%20AI%20Training&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%201.4.38%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-862%20Missing%20Authorization&color=brighgreen)
### Description
The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.
### POC
#### Reference
- https://wpscan.com/vulnerability/3ca9ac21-2bce-4480-9079-b4045b261273
#### Github
No PoCs found on GitHub currently.