CVE-2023-0551

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
Configurations

Configuration 1 (hide)

cpe:2.3:a:minapper:rest_api_to_miniprogram:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - Exploit () https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - Exploit

22 Aug 2023, 16:45

Type Values Removed Values Added
CPE cpe:2.3:a:minapper:rest_api_to_miniprogram:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References (MISC) https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - (MISC) https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - Exploit

16 Aug 2023, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-16 12:15

Updated : 2024-11-21 07:37


NVD link : CVE-2023-0551

Mitre link : CVE-2023-0551

CVE.ORG link : CVE-2023-0551


JSON object : View

Products Affected

minapper

  • rest_api_to_miniprogram
CWE

No CWE.