CVE-2023-5235
Last modified
CVE-2023-5235 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kutethemes | Ovic Responsive Wpbakery | < 1.2.9 |
References
- https://wpscan.com/vulnerability/35c9a954-37fc-4818-a71f-34aaaa0fa3dbThird Party Advisory
- https://wpscan.com/vulnerability/35c9a954-37fc-4818-a71f-34aaaa0fa3dbThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5235?
How severe is CVE-2023-5235?
How do I fix CVE-2023-5235?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-52344In modem-ps-nas-ngmm, there is a possible undefined behavior…5.3
- CVE-2023-52345In modem driver, there is a possible system crash due to imp…6
- CVE-2023-52346In modem driver, there is a possible system crash due to imp…4.4
- CVE-2023-52347In ril service, there is a possible out of bounds write due …5.5
- CVE-2023-52348In ril service, there is a possible out of bounds write due …4.4
- CVE-2023-52349In ril service, there is a possible out of bounds write due …4.4
- CVE-2023-52350In ril service, there is a possible out of bounds write due …4.4
- CVE-2023-52351In ril service, there is a possible out of bounds write due …7.8
- CVE-2023-52352In Network Adapter Service, there is a possible missing perm…5.5
- CVE-2023-52353An issue was discovered in Mbed TLS through 3.5.1. In mbedtl…7.5
- CVE-2023-52354chasquid before 1.13 allows SMTP smuggling because LF-termin…7.5
- CVE-2023-52355An out-of-memory flaw was found in libtiff that could be tri…7.5
Are you affected by CVE-2023-5235?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
