CVE-2023-0551

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
Configurations

Configuration 1 (hide)

cpe:2.3:a:minapper:rest_api_to_miniprogram:*:*:*:*:*:wordpress:*:*

History

07 Nov 2023, 04:00

Type Values Removed Values Added
CWE CWE-352
CWE-284

22 Aug 2023, 16:45

Type Values Removed Values Added
First Time Minapper
Minapper rest Api To Miniprogram
References (MISC) https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - (MISC) https://wpscan.com/vulnerability/de162a46-1fdb-47b9-9a61-f12a2c655a7d - Exploit
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:minapper:rest_api_to_miniprogram:*:*:*:*:*:wordpress:*:*

16 Aug 2023, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-16 12:15

Updated : 2023-11-07 04:00


NVD link : CVE-2023-0551

Mitre link : CVE-2023-0551


JSON object : View

Products Affected

minapper

  • rest_api_to_miniprogram
CWE

No CWE.