The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12396 | The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 19 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-19T20:19:09.595Z
Reserved: 2023-01-17T10:34:09.922Z
Link: CVE-2023-0335
Updated: 2024-08-02T05:10:55.794Z
Status : Modified
Published: 2023-03-27T16:15:08.007
Modified: 2025-02-19T21:15:11.613
Link: CVE-2023-0335
No data.
OpenCVE Enrichment
No data.
EUVD