FunnelKit Checkout <= 3.10.3 - Unauthenticated Arbitrary Content Deletion
medium
The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on an unknown function in all versions up to, and including, 3.10.3. This makes it possible for unauthenticated attackers, to delete arbitrary content.
- CVSS:
- 6.5
- Affected:
- up to 3.10.3
- Fixed in:
- 3.11.0
- Disclosed:
- Dec 27, 2023
CVE-2023-51672 on NVD →
FunnelKit Checkout <= 3.10.3 - Authenticated(Subscriber+) Missing Authorization to Arbitrary Plugin Activation
medium
The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 3.10.3. This makes it possible for authenticated attackers, with subscriber access and above, to activate arbitrary plugins.
- CVSS:
- 4.3
- Affected:
- up to 3.10.3
- Fixed in:
- 3.11.0
- Disclosed:
- Dec 27, 2023
CVE-2023-51670 on NVD →
FunnelKit Checkout <= 3.10.3 - Authenticated(Subscriber+) Missing Authorization to Settings Change
medium
The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 3.10.3. This makes it possible for authenticated attackers, with subscriber access and above, to change the plugin's settings.
- CVSS:
- 4.3
- Affected:
- up to 3.10.3
- Fixed in:
- 3.11.0
- Disclosed:
- Dec 27, 2023
CVE-2023-51671 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database