CVE-2023-0551

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
Configurations

Configuration 1 (hide)

cpe:2.3:a:minapper:rest_api_to_miniprogram:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - Exploit () https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - Exploit

07 Nov 2023, 04:00

Type Values Removed Values Added
CWE CWE-284
CWE-352

22 Aug 2023, 16:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References (MISC) https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - (MISC) https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - Exploit
First Time Minapper
Minapper rest Api To Miniprogram
CPE cpe:2.3:a:minapper:rest_api_to_miniprogram:*:*:*:*:*:wordpress:*:*

16 Aug 2023, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-16 12:15

Updated : 2024-11-21 07:37


NVD link : CVE-2023-0551

Mitre link : CVE-2023-0551

CVE.ORG link : CVE-2023-0551


JSON object : View

Products Affected

minapper

  • rest_api_to_miniprogram
CWE

No CWE.