The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to change page designs.
References
Configurations
History
17 Jan 2024, 22:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-11 09:15
Updated : 2024-02-05 00:22
NVD link : CVE-2023-7019
Mitre link : CVE-2023-7019
CVE.ORG link : CVE-2023-7019
JSON object : View
Products Affected
themeisle
- lightstart
CWE
CWE-862
Missing Authorization