CVE-2023-2584 | WordPress.org

[ad_1]

There is an error with the vulnerability numbers (corrected some time ago as far as I know). 9.6.2 was the version number of the paid plugin, now at 9.10.2.

The 9.4.5.1 is the most recent version for the free plugin, and it doesn’t have the issue you mentioned. This was fix some time ago already.

It may be worth you contacting WPScan to advise them of the false positive:

I can confirm you are correct – it is miss reporting from WP Scan, I have asked them to look into it, as you can see from the mitre site, it agrees that it was resolved after 9.3.6 in the free version: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2584

  • This reply was modified 3 minutes ago by gcuksean. Reason: Adding resolved

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer