CVE-2023-47648
Published: 02 January 2025
Description
Missing Authorization vulnerability in Spider Themes EazyDocs eazydocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through <= 2.3.5.
Security Summary
CVE-2023-47648 is a missing authorization vulnerability (CWE-862) in the EazyDocs WordPress plugin developed by Spider Themes. The flaw enables exploitation of incorrectly configured access control security levels and affects all versions of EazyDocs up to and including 2.3.5.
The vulnerability carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating it can be exploited remotely by unauthenticated attackers with low complexity and no user interaction. Successful exploitation leads to high-impact denial of service, disrupting availability without affecting confidentiality or integrity.
Mitigation details are available in the Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/eazydocs/vulnerability/wordpress-eazydocs-plugin-2-3-3-broken-access-control-vulnerability?_s_id=cve.
Details
- CWE(s)