CVE-2023-51673
WordPress Stylish Price List Plugin <= 7.0.17 is vulnerable to Broken Access Control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – Price Table Builder & QR Code Restaurant Menu: from n/a through 7.0.17.
Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu. Este problema afecta a Stylish Price List – Price Table Builder & QR Code Restaurant Menu: desde n/a hasta 7.0.17.
The Stylish Price List plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on multiple functions in versions up to, and including, 7.0.17. This makes it possible for authenticated attackers, with contributor-level access and above, to duplicate and delete price lists.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-21 CVE Reserved
- 2023-12-27 CVE Published
- 2024-08-02 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/stylish-price-list/wordpress-stylish-price-list-plugin-7-0-17-broken-access-control-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Stylishpricelist Search vendor "Stylishpricelist" | Stylish Price List Search vendor "Stylishpricelist" for product "Stylish Price List" | <= 7.0.17 Search vendor "Stylishpricelist" for product "Stylish Price List" and version " <= 7.0.17" | wordpress |
Affected
|