CVE-2023-0335
Published Mar 27, 2023The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor archive
3 CVEs tagged to vendor wpvar — 0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.
The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.
The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the deactivate() function hooked via init() in versions up to, and in…
Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.