CVE-2023-3510
Last modified
CVE-2023-3510 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloads, which will be triggered when an admin will view the settings of the plugin. The attack could also be perform via CSRF against any authenticated user.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloads, which will be triggered when an admin will view the settings of the plugin. The attack could also be perform via CSRF against any authenticated user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Danialhatami | Ftp Access | <= 1.0 |
References
- https://wpscan.com/vulnerability/76abf4ac-5cc1-41a0-84c3-dff42c659581Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/76abf4ac-5cc1-41a0-84c3-dff42c659581Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3510?
How severe is CVE-2023-3510?
How do I fix CVE-2023-3510?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-35093Broken Access Control vulnerability in StylemixThemes Master…6.5
- CVE-2023-35094Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulne…5.4
- CVE-2023-35095Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2023-35096Cross-Site Request Forgery (CSRF) vulnerability in myCred pl…8.8
- CVE-2023-35097Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-35098Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-3511An issue has been discovered in GitLab EE affecting all vers…3.5
- CVE-2023-35110An issue was discovered jjson thru 0.1.7 allows attackers to…7.5
- CVE-2023-35116jackson-databind through 2.15.2 allows attackers to cause a …4.7
- CVE-2023-3512Relative path traversal vulnerability in Setelsa Security's …7.5
- CVE-2023-35120 PiiGAB M-Bus is vulnerable to cross-site request forgery. A…8.8
- CVE-2023-35121Improper access control in the Intel(R) oneAPI DPC++/C++ Com…7.8
Are you affected by CVE-2023-3510?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
