Description
The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset network access tokens.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12461 | The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset network access tokens. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Social Warfare <= 4.3.0 - Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
|
Mon, 13 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:51:04.230Z
Reserved: 2023-01-19T14:06:58.319Z
Link: CVE-2023-0402
Updated: 2024-08-02T05:10:55.925Z
Status : Modified
Published: 2023-01-19T15:15:13.813
Modified: 2026-04-08T18:17:42.207
Link: CVE-2023-0402
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD