CVE · Medium

CVE-2023-29239 — LuckyWP Scripts Control [luckywp-scripts-control] < 1.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-29239 LuckyWP Scripts Control [luckywp-scripts-control] < 1.2.2 Missing Authorization Medium 5.4 < 1.2.2 1.2.2 2023-08-28

CVE-2023-29239

The LuckyWP Scripts Control plugin through version 1.2.1 contains a cross-site request forgery vulnerability stemming from inadequate nonce verification in the ItemController.php administrative file. An attacker could exploit this flaw by deceiving a site administrator into clicking a malicious link, allowing the attacker to perform unauthorized actions including adding, editing, deleting, enabling, disabling, and reordering items. The vulnerability affects all versions up to and including 1.2.1 and has been patched in version 1.2.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.