CVE-2023-1597 describes a critical vulnerability in the tagDiv Cloud Library WordPress plugin prior to version 2.7. This flaw allows unauthenticated attackers to exploit an AJAX action lacking authorization and CSRF protection, enabling them to modify arbitrary user metadata. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk of privilege escalation, as attackers can set themselves as administrators. Despite its severity, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7CPE matchmatch criteria | cpe:2.3:a:tagdiv:cloud_library:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.