AWeber <= 7.3.9 - Missing Authorization via AJAX actions
2023-11-13 00:00
Abdi PranataStrategic Overview
StatusPatched in 7.3.10
Affected PluginAWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth
Affected Version
<= 7.3.9CVSS6.3Medium
CVE
CVE-2023-47757Vulnerability Overview
The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions hooked by AJAX actions in all versions up to, and including, 7.3.9. This makes it possible for subscribers and higher to create and publish pages and modify landing pages.
Technical Analysis
REMEDIATION: Update to version 7.3.10, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C