CVSS v3
8.8
HIGH
EPSS Score
25.6 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_screen_options[option]' and 'wp_screen_options[value]' parameters during a screen option update.
Technical details
- Published
- 2023-06-06
Frequently asked questions
What is CVE-2023-2833?
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_screen_options[option]' and 'wp_screen_options[value]' parameters during a screen option update.
Is CVE-2023-2833 actively exploited?
Active exploitation of CVE-2023-2833 has not been confirmed. The EPSS score is 25.6%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2023-2833?
CVE-2023-2833 has a CVSS v3 base score of 8.8 (HIGH severity).
Is CVE-2023-2833 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2023 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).