CVE Database · CVE-2023-5611
CVSS v3.1
5.3
EPSS
0.27%
Published
Nov 27, 2023
Modified
Jan 16, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NWeaknesses (CWE)
Affected Products (1)
References (2)