ZeroHour

CVE-2023-1597

PoC
CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
Description

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

Vendors
tagdiv
Products
cloud library
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.