CVE-2023-6029 is a critical authorization bypass vulnerability affecting the EazyDocs WordPress plugin prior to version 2.3.6. This flaw allows unauthenticated attackers to delete arbitrary WordPress posts and manage EazyDocs documents and sections due to missing authorization and CSRF checks. With a CVSS score of 7.5 (High), it presents a significant risk of data manipulation and denial of service, requiring no user interaction or prior authentication. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion, the vulnerability's ease of exploitation makes it a serious concern for affected WordPress sites.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.6CPE matchmatch criteria | cpe:2.3:a:spider-themes:eazydocs:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.