Medium severity4.3NVD Advisory· Published Jan 11, 2024· Updated Apr 8, 2026
CVE-2023-6883
CVE-2023-6883
Description
The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 6.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions, such as modifying the plugin's Facebook and Instagram access tokens and updating group IDs.
Affected products
1- cpe:2.3:a:easysocialfeed:easy_social_feed:*:*:*:*:-:wordpress:*:*Range: <=6.5.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/3deee9b5-2e36-447d-a492-e22e3dc6a5abnvdProductThird Party Advisory
- plugins.trac.wordpress.org/changeset/3012165/easy-facebook-likeboxnvdRelease Notes
News mentions
0No linked articles in our index yet.