CVE Database
/

CVE-2023-1597

Back to search

CVE-2023-1597

Published: Jul 10, 2023

Modified: Nov 8, 2024

PUBLISHED

Description

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

VendorProductVersions

Unknown

tagDiv Cloud Library

affected
0 - < 2.7

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now