4.3

CVE-2023-4242

FULL - Customer <= 2.2.3 - Authenticated(Subscriber+) Information Disclosure via Health Check

FULL - Customer <= 2.2.3 - Authenticated(Subscriber+) Information Disclosure via Health Check

The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to obtain sensitive information about the site configuration as disclosed by the WordPress health check.
Mögliche Gegenmaßnahme
FULL – Cliente: Update to version 2.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FullFull - Customer SwPlatformwordpress Version <= 2.2.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt FULL – Cliente
Version *-2.2.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.344
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://plugins.trac.wordpress.org/browser/full-customer/tags/1.1.0/app/api/Health.php
Product
https://www.wordfence.com/threat-intel/vulnerabilities/id/a77d0fb5-8829-407d-a40a-169cf0c5f837?source=cve
Third Party Advisory
https://plugins.trac.wordpress.org/browser/full-customer/tags/2.3/app/api/Controller.php?rev=2951561
https://www.wordfence.com/threat-intel/vulnerabilities/id/a77d0fb5-8829-407d-a40a-169cf0c5f837
Third Party Advisory