CVE-2023-2078 affects the "Buy Me a Coffee – Button and Widget Plugin" for WordPress, allowing authenticated users with low privileges, like subscribers, to modify plugin settings due to missing capability checks in several functions. This vulnerability has a CVSS score of 4.3 (Medium), indicating a low-complexity attack that could lead to unauthorized data modification without impacting confidentiality or availability. While no active exploits, Metasploit modules, or public exploit code are currently available, and community discussion is minimal, organizations should still patch affected versions up to 3.7 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8CPE matchmatch criteria | cpe:2.3:a:buymeacoffee:buy_me_a_coffee:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.