WordPress security by component
Staff / Employee Business Directory for Active Directory
Plugin description
Staff / Employee Business Directory for Active Directory is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 27, 2023; the highest CVE/CNA score is 2.2.
Plugin slug:
ldap-ad-staff-employee-directory-searchLatest vulnerability
CVE-2023-4505: Staff / Employee Business Directory for Active Directory: Privilege escalation or authentication bypass
Staff / Employee Business Directory for Active Directory is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
| Safe version |
|
||
|---|---|---|---|
| Sep 27, 2023 |
CVE-2023-4505
Staff / Employee Business Directory for Active Directory: Privilege escalation or authentication bypass
Staff / Employee Business Directory for Active Directory is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE2.2
NVD4.9
|