The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog folders
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-02-04T17:20:37.952Z

Reserved: 2023-03-24T17:48:26.514Z

Link: CVE-2023-1624

cve-icon Vulnrichment

Updated: 2024-08-02T05:57:24.258Z

cve-icon NVD

Status : Modified

Published: 2023-04-24T19:15:09.693

Modified: 2025-02-04T18:15:32.703

Link: CVE-2023-1624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.