{ "id": "CVE-2023-6279", "sourceIdentifier": "contact@wpscan.com", "published": "2024-01-29T15:15:09.343", "lastModified": "2024-11-21T08:43:31.597", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update arbitrary blog options and set them to 'activated' which could lead to DoS when using a specific option name" }, { "lang": "es", "value": "El complemento de WordPress Woostify Sites Library anterior a 1.4.8 no tiene autorizaci\u00f3n en una acci\u00f3n AJAX, lo que permite a cualquier usuario autenticado, como un suscriptor, actualizar opciones de blog arbitrarias y configurarlas como \"activated\", lo que podr\u00eda provocar DoS al usar un nombre de opci\u00f3n espec\u00edfico." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH" }, "exploitabilityScore": 2.8, "impactScore": 4.2 } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-862" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:wootsify:sites_library:*:*:*:*:*:wordpress:*:*", "versionEndExcluding": "1.4.8", "matchCriteriaId": "31435716-69E0-47D7-9AE3-7067A5C1E237" } ] } ] } ], "references": [ { "url": "https://wpscan.com/vulnerability/626bbc7d-0d0f-4418-ac61-666278a1cbdb/", "source": "contact@wpscan.com", "tags": [ "Exploit", "Third Party Advisory" ] }, { "url": "https://wpscan.com/vulnerability/626bbc7d-0d0f-4418-ac61-666278a1cbdb/", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Third Party Advisory" ] } ] }