CVE-2023-47191
WordPress Youzify Plugin <= 1.2.2 is vulnerable to Insecure Direct Object References (IDOR)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.
Vulnerabilidad de omisión de autorización a través de clave controlada por el usuario en KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress. Este problema afecta a Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: desde n/a hasta 1.2.2.
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-10-31 CVE Reserved
- 2023-11-03 CVE Published
- 2024-08-02 CVE Updated
- 2024-12-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/youzify/wordpress-youzify-plugin-1-2-2-insecure-direct-object-reference-idor-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kainelabs Search vendor "Kainelabs" | Youzify Search vendor "Kainelabs" for product "Youzify" | < 1.2.3 Search vendor "Kainelabs" for product "Youzify" and version " < 1.2.3" | wordpress |
Affected
|