CVE-2023-7019
11.01.2024, 09:15
The LightStart Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to change page designs.Enginsight
Vendor | Product | Version |
---|---|---|
themeisle | lightstart | 𝑥 ≤ 2.6.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References