Missing Authorization vulnerability in weDevs WP ERP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through 1.12.6.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-50054 Missing Authorization vulnerability in weDevs WP ERP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through 1.12.6.
Fixes

Solution

Update the WordPress WP ERP plugin to the latest available version (at least 1.12.7).


Workaround

No workaround given by the vendor.

History

Fri, 31 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wedevs
Wedevs wp Erp
CPEs cpe:2.3:a:wedevs:wp_erp:*:*:*:*:*:wordpress:*:*
Vendors & Products Wedevs
Wedevs wp Erp

Fri, 03 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jan 2025 12:15:00 +0000

Type Values Removed Values Added
Title WordPress WP ERP plugin <= 1.12.6 - Broken Access Control vulnerability

Thu, 02 Jan 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in weDevs WP ERP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through 1.12.6.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-01-03T19:10:50.383Z

Reserved: 2023-10-12T12:45:14.808Z

Link: CVE-2023-45765

cve-icon Vulnrichment

Updated: 2025-01-02T17:38:49.244Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-02T12:15:09.970

Modified: 2025-01-31T16:50:21.233

Link: CVE-2023-45765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses