CVE-2023-0551

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
Configurations

Configuration 1 (hide)

cpe:2.3:a:minapper:rest_api_to_miniprogram:*:*:*:*:*:wordpress:*:*

Information

Published : 2023-08-16 12:15

Updated : 2023-08-22 16:45


NVD link : CVE-2023-0551

Mitre link : CVE-2023-0551


JSON object : View

Products Affected

minapper

  • rest_api_to_miniprogram
CWE
CWE-284

Improper Access Control

CWE-352

Cross-Site Request Forgery (CSRF)