Unrated severityNVD Advisory· Published Apr 17, 2023· Updated Feb 6, 2025
TF Random Numbers < 2.0.1 - Subscriber+ Arbitrary Option Update
CVE-2023-0889
Description
Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/Themeflection Numbersdescription
- Range: <2.0.1
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/c39473a7-47fc-4bce-99ad-28d03f41e74emitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.