Vulnerability Description
The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Greeklish-Permalink Project | Greeklish-Permalink | <= 3.3 |
References
- https://wpscan.com/vulnerability/45878983-7e9b-49c2-8f99-4c28aab24f09ExploitThird Party Advisory
- https://wpscan.com/vulnerability/45878983-7e9b-49c2-8f99-4c28aab24f09ExploitThird Party Advisory
FAQ
What is CVE-2023-2495?
CVE-2023-2495 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to ...
How severe is CVE-2023-2495?
CVE-2023-2495 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2495?
Check the references section above for vendor advisories and patch information. Affected products include: Greeklish-Permalink Project Greeklish-Permalink.