Pods - Custom Content Types and Fields - Missing Authorization

2024-03-28 00:00
Nex Team

Strategic Overview

Status
Patched in 2.7.31.2
Affected Version2.7.31 – < 3.0.10.2 · 3 branches
CVSS4.3Medium
CVECVE-2023-6965
View all Pods – Custom Content Types and Fields vulnerabilities

Vulnerability Overview

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to create pods and users (with default role).

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 2.7.31.2, 2.8.23.2, 2.9.19.2, 3.0.10.2 --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C