ZeroHour

CVE-2023-0335

PoC
CVSS 3.1
6.5 medium
EPSS
1%p61
Published
()
Modified
Description

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.

Vendors
wpvar
Products
wp shamsi
Ecosystems
WordPress
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.