CVE-2023-0328

MEDIUM

WPCode < 2.0.7 - Authenticated Inadequate Privilege Checks in AJAX Actions

Title source: llm
STIX 2.1

Description

The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/3c4318a9-a3c5-409b-a52e-edd8583c3c43

Scores

CVSS v3 4.3
EPSS 0.0080
EPSS Percentile 51.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
wpcode/wpcode < 2.0.7
Published Mar 06, 2023
Tracked Since Feb 18, 2026