Description
The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33979 | The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF. |
References
History
Tue, 12 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-12T14:03:06.737Z
Reserved: 2023-05-03T14:19:24.270Z
Link: CVE-2023-2495
Updated: 2024-08-02T06:26:09.230Z
Status : Modified
Published: 2023-07-10T16:15:51.187
Modified: 2024-11-21T07:58:43.470
Link: CVE-2023-2495
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD