VYPR
Medium severity5.4NVD Advisory· Published Dec 9, 2024· Updated Apr 28, 2026

CVE-2023-28417

CVE-2023-28417

Description

Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in AlexaCRM Dynamics 365 Integration plugin for WordPress allows unprivileged users to exploit incorrectly configured access control, leading to unauthorized actions.

Vulnerability

Overview

CVE-2023-28417 is a missing authorization vulnerability in the AlexaCRM Dynamics 365 Integration plugin for WordPress, affecting versions up to 1.3.12. The plugin fails to properly enforce access control checks, allowing users with low privileges to access or execute functions that should be restricted to higher-privileged roles [1].

Exploitation

An attacker who has authenticated with a minimal WordPress role (e.g., subscriber) can exploit the missing authorization to perform actions intended for administrators or other privileged users. The vulnerability stems from a lack of authorization, authentication, or nonce token checks in certain plugin functions [1]. This type of broken access control is frequently targeted in mass-exploit campaigns, as it can be automated against thousands of sites [1].

Impact

Successful exploitation could allow an attacker to modify Dynamics 365 integration settings, access sensitive data, or perform other unauthorized operations within the WordPress environment. While the CVSS score is 5.4 (Medium), the practical impact depends on the specific misconfigured access control levels present in the plugin [1].

Mitigation

The vulnerability has been patched in version 1.3.13 of the plugin. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not possible, consulting a hosting provider or web developer is recommended [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.