← WordPress Vulnerabilities
WordPress security by component

Staff / Employee Business Directory for Active Directory

Staff / Employee Business Directory for Active Directory is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 27, 2023; the highest CVE/CNA score is 2.2.

Plugin slug: ldap-ad-staff-employee-directory-search

CVE-2023-4505: Staff / Employee Business Directory for Active Directory: Privilege escalation or authentication bypass

Staff / Employee Business Directory for Active Directory is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.

PublishedSep 27, 2023
Safe version guidanceSee mitigation notes
Safe version
Sep 27, 2023 CVE-2023-4505
Staff / Employee Business Directory for Active Directory: Privilege escalation or authentication bypass
Staff / Employee Business Directory for Active Directory is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE2.2
NVD4.9