Vulnerability Description
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| G5Plus | Essential Real Estate | < 4.4.0 |
References
- https://wpscan.com/vulnerability/96396a22-f523-4c51-8b72-52be266988aaExploitThird Party Advisory
- https://wpscan.com/vulnerability/96396a22-f523-4c51-8b72-52be266988aaExploitThird Party Advisory
FAQ
What is CVE-2023-6139?
CVE-2023-6139 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Deni...
How severe is CVE-2023-6139?
CVE-2023-6139 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6139?
Check the references section above for vendor advisories and patch information. Affected products include: G5Plus Essential Real Estate.