CVE-2023-3053
03.06.2023, 00:15
The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. This makes it possible for authenticated attackers to create a post with any post type and post status.Enginsight
Vendor | Product | Version |
---|---|---|
azexo | page_builder_with_image_map_by_azexo | 𝑥 ≤ 1.27.133 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References