CVE-2023-36681 (GCVE-0-2023-36681)
Vulnerability from cvelistv5
Published
2024-12-13 14:23
Modified
2026-04-28 16:08
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-862 - Missing Authorization
Summary
Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.2.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Cool Plugins | Cryptocurrency Widgets – Price Ticker & Coins List |
Version: n/a < |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-36681",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-12-13T18:34:14.147214Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-12-13T18:34:32.340Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "cryptocurrency-price-ticker-widget",
"product": "Cryptocurrency Widgets \u2013 Price Ticker \u0026 Coins List",
"vendor": "Cool Plugins",
"versions": [
{
"changes": [
{
"at": "2.6.3",
"status": "unaffected"
}
],
"lessThanOrEqual": "2.6.2",
"status": "affected",
"version": "n/a",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Abdi Pranata (Patchstack Alliance)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMissing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets \u2013 Price Ticker \u0026 Coins List allows Exploiting Incorrectly Configured Access Control Security Levels.\u003c/p\u003e\u003cp\u003eThis issue affects Cryptocurrency Widgets \u2013 Price Ticker \u0026 Coins List: from n/a through 2.6.2.\u003c/p\u003e"
}
],
"value": "Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets \u2013 Price Ticker \u0026 Coins List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets \u2013 Price Ticker \u0026 Coins List: from n/a through 2.6.2."
}
],
"impacts": [
{
"capecId": "CAPEC-180",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:08:31.742Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/cryptocurrency-price-ticker-widget/vulnerability/wordpress-cryptocurrency-widgets-price-ticker-coins-list-plugin-2-6-2-broken-access-control-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Cryptocurrency Widgets \u2013 Price Ticker \u0026 Coins List plugin to the latest available version (at least 2.6.3)."
}
],
"value": "Update the WordPress Cryptocurrency Widgets \u2013 Price Ticker \u0026 Coins List plugin to the latest available version (at least 2.6.3)."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "WordPress Cryptocurrency Widgets \u2013 Price Ticker \u0026 Coins List plugin \u003c= 2.6.2 - Broken Access Control vulnerability",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2023-36681",
"datePublished": "2024-12-13T14:23:48.283Z",
"dateReserved": "2023-06-26T05:35:13.537Z",
"dateUpdated": "2026-04-28T16:08:31.742Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2023-36681\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"yes\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-12-13T18:34:14.147214Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-12-13T18:34:26.988Z\"}}], \"cna\": {\"title\": \"WordPress Cryptocurrency Widgets \\u2013 Price Ticker \u0026 Coins List plugin \u003c= 2.6.2 - Broken Access Control vulnerability\", \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Abdi Pranata | Patchstack Bug Bounty Program\"}], \"impacts\": [{\"capecId\": \"CAPEC-180\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"Exploiting Incorrectly Configured Access Control Security Levels\"}]}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.3, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"LOW\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"NONE\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"CoolHappy\", \"product\": \"Cryptocurrency Widgets \\u2013 Price Ticker \u0026 Coins List\", \"versions\": [{\"status\": \"affected\", \"changes\": [{\"at\": \"2.6.3\", \"status\": \"unaffected\"}], \"version\": \"0\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"2.6.2\"}], \"packageName\": \"cryptocurrency-price-ticker-widget\", \"collectionURL\": \"https://wordpress.org/plugins\", \"defaultStatus\": \"unaffected\"}], \"datePublic\": \"2026-04-22T14:34:58.725Z\", \"references\": [{\"url\": \"https://patchstack.com/database/Wordpress/Plugin/cryptocurrency-price-ticker-widget/vulnerability/wordpress-cryptocurrency-widgets-price-ticker-coins-list-plugin-2-6-2-broken-access-control-vulnerability?_s_id=cve\", \"tags\": [\"vdb-entry\"]}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"Missing Authorization vulnerability in CoolHappy Cryptocurrency Widgets \\u2013 Price Ticker \u0026 Coins List cryptocurrency-price-ticker-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets \\u2013 Price Ticker \u0026 Coins List: from n/a through \u003c= 2.6.2.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"Missing Authorization vulnerability in CoolHappy Cryptocurrency Widgets \\u2013 Price Ticker \u0026 Coins List cryptocurrency-price-ticker-widget allows Exploiting Incorrectly Configured Access Control Security Levels.\u003cp\u003eThis issue affects Cryptocurrency Widgets \\u2013 Price Ticker \u0026 Coins List: from n/a through \u003c= 2.6.2.\u003c/p\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-862\", \"description\": \"Missing Authorization\"}]}], \"providerMetadata\": {\"orgId\": \"21595511-bba5-4825-b968-b78d1f9984a3\", \"shortName\": \"Patchstack\", \"dateUpdated\": \"2026-04-23T13:50:07.046Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2023-36681\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-04-23T13:50:07.046Z\", \"dateReserved\": \"2023-06-26T05:35:13.537Z\", \"assignerOrgId\": \"21595511-bba5-4825-b968-b78d1f9984a3\", \"datePublished\": \"2024-12-13T14:23:48.283Z\", \"assignerShortName\": \"Patchstack\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…