Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through 1.9.8.
Fixes

Solution

Update the WordPress WP Docs plugin to the latest available version (at least 1.9.9).


Workaround

No workaround given by the vendor.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00201}

epss

{'score': 0.00226}


Thu, 27 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Androidbubble
Androidbubble wp Docs
CPEs cpe:2.3:a:androidbubble:wp_docs:*:*:*:*:*:wordpress:*:*
Vendors & Products Androidbubble
Androidbubble wp Docs

Mon, 09 Dec 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Dec 2024 11:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through 1.9.8.
Title WordPress WP Docs plugin <= 1.9.8 - Broken Access Control
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2024-12-09T13:49:55.924Z

Reserved: 2023-04-19T12:33:22.776Z

Link: CVE-2023-30873

cve-icon Vulnrichment

Updated: 2024-12-09T13:48:31.646Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-09T13:15:28.413

Modified: 2025-02-27T20:54:25.290

Link: CVE-2023-30873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.