CVE Vulnerabilities

CVE-2023-5098

Published: Oct 31, 2023 | Modified: Apr 23, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string true, which could lead to a variety of outcomes, including DoS.

Affected Software

NameVendorStart VersionEnd Version
Campaign_monitor_optin_catFatcatapps*2.5.6 (excluding)

References