CVE-2023-2434

Publication date

2023-05-31 03:36:10

Family

Wordfence

State

PUBLISHED

Description

The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the reset function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.