CRITICAL
Wordapp <= 1.6.0 - Authorization Bypass through Use of Insufficiently Unique Cryptographic Signature
Published May 31, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.53%
Description
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the plugin to change the 'validation_token' in the plugin config, providing access to the plugin's remote control functionalities, such as creating an admin access URL, which can be used for privilege escalation.
Affected products
-
- Version 0StatusaffectedConstraints<=1.6.0
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34423 Advisory
- https://lana.report/publication/6e779e9a-e0f9-4102-9f0b-ad46e9c4533f/
- https://plugins.trac.wordpress.org/browser/wordapp/trunk/includes/access.php#L28 Patch
- https://plugins.trac.wordpress.org/browser/wordapp/trunk/includes/config.php#L59 Patch
- https://plugins.trac.wordpress.org/browser/wordapp/trunk/includes/pdx.php#L64 Patch
- https://plugins.trac.wordpress.org/changeset/3063322/wordapp
- https://www.wordfence.com/threat-intel/vulnerabilities/id/80440bfa-4a02-4441-bbdb-52d7dd065a9d?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published May 31, 2023
Updated Apr 8, 2026
Reserved May 30, 2023
Link CVE-2023-2987
CISA Vulnrichment
Updated Jan 13, 2025
ENISA EUVD
EUVD-2023-34423 Assigner Wordfence
Published May 31, 2023
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2023-34423