CVE-2023-4626
MEDIUMDescription
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and including, 4.3. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladiflow_hook_configs' option.
Is your site exposed to CVE-2023-4626?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| ladipage | ladipage |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-4626? +
How severe is CVE-2023-4626? +
What products are affected by CVE-2023-4626? +
How do I check if I'm vulnerable to CVE-2023-4626? +
Related Vulnerabilities
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() …
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() …
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() …
The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() …