CVE Vulnerabilities

CVE-2023-2833

Improper Privilege Management

Published: Jun 06, 2023 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the rx_set_screen_options function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the wp_screen_options[option] and wp_screen_options[value] parameters during a screen option update.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Reviewx Wpdeveloper * 1.6.13 (including)

Potential Mitigations

References