CVE-2023-4728
—CVSS 3.1
5.4 medium
EPSS
<1%p25
Published
()
Modified
Description
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to change the LadiPage key (a key fully controlled by the attacker), enabling them to freely create new pages, including web pages that trigger stored XSS
- Vendors
- ladipage
- Products
- ladipage
- Ecosystems
- WordPress
- Weakness
- CWE-862, CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.