The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-10-31T13:54:44.176Z

Updated: 2024-08-02T07:44:53.809Z

Reserved: 2023-09-20T19:24:32.385Z

Link: CVE-2023-5098

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-10-31T14:15:12.230

Modified: 2023-11-08T18:33:48.503

Link: CVE-2023-5098

cve-icon Redhat

No data.