1 results (0.001 seconds)
CVSS: 4.3EPSS: %CPEs: 1EXPL: 0
CVE-2023-25068 – Magazine Edge <= 1.13 - Authenticated (Subscriber+) Arbitrary Plugin Activation
https://notcve.org/view.php?id=CVE-2023-25068
The Magazine Edge theme for WordPress is vulnerable to authorization bypass in versions up to, and including 1.13, due to a missing capability check. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to activate arbitrary plugins. • CWE-862: Missing Authorization •