CVE-2023-6598 Information

Description

The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship speedycache_img_update_settings speedycache_preloading_add_settings and speedycache_preloading_delete_resource functions in all versions up to and including 1.1.3. This makes it possible for authenticated attackers with subscriber-level access and above to update plugin options.

Reference

https://www.wordfence.com/threat-intel/vulnerabilities/id/db8cfdba-f3b2-45dc-9be7-6f6374fd5f39?source=cve https://plugins.trac.wordpress.org/changeset/3010577/speedycache

Share on: