MEDIUM
Strong Testimonials <= 3.1.12 - Authenticated(Contributor+) Improper Authorization to Views Modification
Published Jun 7, 2024
4.3
MEDIUMCVSS 3.1
EPSS 0.28%
Description
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify favorite views.
Affected products
-
- Version 0StatusaffectedConstraints<=3.1.12
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Wpchill | Strong Testimonials | unaffected |
|
- < 3.1.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58722 Advisory
- https://plugins.trac.wordpress.org/changeset/3097409/strong-testimonials/tags/3.1.13/admin/views.php Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c3277d93-4f47-445b-a193-ff990b55d054?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jun 7, 2024
Updated Apr 8, 2026
Reserved Dec 4, 2023
Link CVE-2023-6491
CISA Vulnrichment
Updated Jun 7, 2024
ENISA EUVD
EUVD-2023-58722 Assigner Wordfence
Published Jun 7, 2024
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2023-58722