CVE-2023-5411
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2023-5411 is a vulnerability found in the Funnelforms Free plugin for WordPress, specifically in versions up to and including 3.4. The vulnerability allows authenticated attackers with subscriber-level permissions or higher to modify certain post values due to a missing capability check on the fnsf_af2_save_post function. It is important to note that the extent of modification is limited as fixed values are passed to the wp_update_post function. The risk score for this vulnerability is 5, with a base severity of MEDIUM and a base score of 4.3. The exploitability score is 2.8, and the potential impact includes low integrity impact and no confidentiality impact or user interaction required. It is classified as CWE-862 (MISSING AUTHORIZATION).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.