Description
The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57563 | The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks. |
References
History
Thu, 14 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-11T17:05:31.530Z
Reserved: 2023-09-27T16:10:04.196Z
Link: CVE-2023-5235
Updated: 2024-08-02T07:52:08.462Z
Status : Modified
Published: 2024-01-08T19:15:09.790
Modified: 2025-06-11T17:15:37.917
Link: CVE-2023-5235
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD