CVE · Medium

CVE-2023-47874 — Perfmatters [perfmatters] < 2.1.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-47874 Perfmatters [perfmatters] < 2.1.7 Missing Authorization Medium 5.4 < 2.1.7 2.1.7 2023-11-20

CVE-2023-47874

The Perfmatters WordPress plugin before version 2.1.7 contains a broken access control vulnerability that was discovered and reported by Dave Jong via Patchstack. The flaw stems from insufficient authorization checks in a plugin function, allowing unauthenticated or low-privileged users to perform actions intended for higher-privileged roles. This security issue has been resolved in version 2.1.7 and users should update their installations immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.