← Back to CVE List

CVE-2023-0551

Published: 2023-08-16T12:15Z
Last Modified: 2024-11-21T07:37Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments > MITRE Terms of Use apply – see LICENSE‑MITRE.txt