CVE-2023-28168
WordPress WordPress Console plugin <= 0.3.9 - Broken Access Control vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9.
The WordPress Console plugin for WordPress is vulnerable to unauthorized modification of data and execution of files due to missing authorization in several files such as reload.php, complete.php, and query that is also missing direct file access controls in versions up to, and including, 0.3.9. This makes it possible for unauthenticated attackers to unset the '$_SESSION['console_vars']' and '$_SESSION['partial']' variables and potentially achieve remote code execution if they can successfully exploit the type juggling weakness in query.php.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-03-13 CVE Reserved
- 2023-03-14 CVE Published
- 2024-12-09 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
- CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/wordpress/plugin/wordpress-console/vulnerability/wordpress-wordpress-console-plugin-0-3-9-broken-access-control-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Console Search vendor "Wordpress Console" | Wordpress Console Search vendor "Wordpress Console" for product "Wordpress Console" | >= 0.0.0 <= 0.3.9 Search vendor "Wordpress Console" for product "Wordpress Console" and version " >= 0.0.0 <= 0.3.9" | en |
Affected
|