8.8
CVSSv3

CVE-2023-47840

Published: 29/12/2023 Updated: 04/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a up to and including 1.5.2.

Vulnerable Product Search on Vulmon Subscribe to Product

qodeinteractive qode essential addons

Github Repositories

Qode Essential Addons <= 1.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

CVE-2023-47840 Qode Essential Addons &lt;= 152 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation Description: The Qode Essential Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin() function in all versions up to, and including, 152 This mak