Vulnerability Description
The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fatcatapps | Campaign Monitor Optin Cat | < 2.5.6 |
References
- https://wpscan.com/vulnerability/3167a83c-291e-4372-a42e-d842205ba722ExploitThird Party Advisory
- https://wpscan.com/vulnerability/3167a83c-291e-4372-a42e-d842205ba722ExploitThird Party Advisory
FAQ
What is CVE-2023-5098?
CVE-2023-5098 is a vulnerability with a CVSS score of 8.1 (HIGH). The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which...
How severe is CVE-2023-5098?
CVE-2023-5098 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5098?
Check the references section above for vendor advisories and patch information. Affected products include: Fatcatapps Campaign Monitor Optin Cat.