CVE-2023-5235

HIGH

Ovic Responsive WPBakery < 1.2.9 - Authenticated Object Injection via AJAX Action

Title source: llm
STIX 2.1

Description

The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks.

References (1)

Core 1
Core References
Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/35c9a954-37fc-4818-a71f-34aaaa0fa3db

Scores

CVSS v3 8.8
EPSS 0.0056
EPSS Percentile 42.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
kutethemes/ovic_responsive_wpbakery < 1.2.9
Published Jan 08, 2024
Tracked Since Feb 18, 2026