Fiche vulnérabilité
CVE-2023-2987 : faille critique wordapp wordapp (CVSS 9.8)
Description
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the plugin to change the 'validation_token' in the plugin config, providing access to the plugin's remote control functionalities, such as creating an admin access URL, which can be used for privilege escalation.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 31 mai 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- wordapp wordapp
Références
- Fiche CVE-2023-2987 sur le NVD (NIST)
- lana.report/publication/6e779e9a…
- plugins.trac.wordpress.org/browser/wordapp/trunk/includes/access.php
- plugins.trac.wordpress.org/browser/wordapp/trunk/includes/config.php
- plugins.trac.wordpress.org/browser/wordapp/trunk/includes/pdx.php
- plugins.trac.wordpress.org/changeset/3063322/wordapp
- wordfence.com/threat…