The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-10-31T13:54:44.176Z

Updated: 2025-04-23T16:10:21.446Z

Reserved: 2023-09-20T19:24:32.385Z

Link: CVE-2023-5098

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-10-31T14:15:12.230

Modified: 2025-04-23T17:16:49.753

Link: CVE-2023-5098

cve-icon Redhat

No data.