CVE Published: 11/07/2023 |
CVE Updated: 08/11/2024 |
CVE Year: 2023 Source: Wordfence |
Vendor: buymeacoffee |
Product: Buy Me a Coffee – Button and Widget Plugin Status : PUBLISHED
CVE-2023-2078 Description
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including, 3.7. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to update the plugins settings. CVE-2023-25030 may be a duplicate of this issue.
Metrics
CVSS Version: 3.1 |
Base Score: 7.3 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L