Vulnerability Description
The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages from the all-users messenger.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Riverforest-Wp | All Users Messenger | <= 1.24 |
References
- https://wpscan.com/vulnerability/682c0226-28bd-4051-830d-8b679626213dExploitThird Party Advisory
- https://wpscan.com/vulnerability/682c0226-28bd-4051-830d-8b679626213dExploitThird Party Advisory
FAQ
What is CVE-2023-4023?
CVE-2023-4023 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages from the all-users messenger.
How severe is CVE-2023-4023?
CVE-2023-4023 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4023?
Check the references section above for vendor advisories and patch information. Affected products include: Riverforest-Wp All Users Messenger.