VYPR
Medium severity5.3NVD Advisory· Published Dec 9, 2024· Updated Apr 29, 2026

CVE-2023-51362

CVE-2023-51362

Description

Missing Authorization vulnerability in Premio My Sticky Elements mystickyelements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Sticky Elements: from n/a through <= 2.1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in My Sticky Elements plugin allows unauthenticated access control bypass, affecting versions up to 2.1.3.

Vulnerability

Overview

CVE-2023-51362 is a missing authorization vulnerability in the Premio My Sticky Elements plugin for WordPress. The plugin fails to properly enforce access controls on certain functions, allowing unprivileged users to execute actions that should require higher privileges [1]. This broken access control issue affects all versions from n/a through 2.1.3.

Exploitation

Attackers can exploit this vulnerability without needing any authentication or by leveraging low-privileged accounts. The Patchstack advisory notes that this type of vulnerability is commonly used in mass-exploit campaigns, targeting thousands of websites regardless of their size or popularity [1]. No special network position is required beyond typical web access.

Impact

Successful exploitation could allow an attacker to perform unauthorized operations, potentially leading to site compromise, data exposure, or further privilege escalation. While the CVSS score is 5.3 (Medium), the actual risk depends on the specific functions exposed [1].

Mitigation

The vulnerability has been patched in version 2.1.4. Users are strongly advised to update immediately or enable auto-updates via Patchstack [1]. If updating is not possible, consulting a hosting provider or web developer is recommended.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.