Web / CMS

Authentication & Access Bypass

WPCode <= 2.0.6 - Contributor+ WPCode.com Library Connection Modification

WPCode <= 2.0.6 – Contributor+ WPCode.com Library Connection Modification The plugin does not have adequate privilege checks in place for several AJAX actions, only checking the nonce.

4.3
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS66
PUBLISHED
2023-06-19
CVE IDs
CVE-2023-0328
VENDORS
WPCode
PUBLIC EXPLOIT
PoC public
CWE
CWE-863
PRODUCT
WPCode Insert Headers and Footers (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

WPCode <= 2.0.6 – Contributor+ WPCode.com Library Connection Modification

The plugin does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).

Vulnerability details

Vulnerability details

CVE-2023-0328
CWE-863
Medium | 4.3

WPCode <= 2.0.6 – Contributor+ WPCode.com Library Connection Modification The plugin does not have adequate privilege checks in place for several AJAX actions, only checking the nonce.

Auth:
Any authenticated user (remote)
Impact:
Limited data tampering
DISCLOSURE

Disclosure timeline

2023-01-10 Reported On

2023-02-09 Made Public On

2023-02-07 Fixed On

Credits

Sanjay Das