Medium severity6.5NVD Advisory· Published Apr 17, 2023· Updated Jun 17, 2026
CVE-2023-0889
CVE-2023-0889
Description
Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:metagauss:themeflection_numbers:*:*:*:*:*:wordpress:*:*Range: <2.0.1
- WordPress/Themeflection Numbersdescription
- Range: <2.0.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/c39473a7-47fc-4bce-99ad-28d03f41e74envdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.