| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-59162 | The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX functions in the /core/core_ajax.php file in all versions up to, and including, 9.5.20. This makes it possible for authenticated attackers, with subscriber access and above, to update and retrieve billing and bank details, update and reset the plugin's settings, and update languages as well as other lower-severity actions. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 27 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-02T08:50:06.854Z
Reserved: 2023-12-19T21:26:17.585Z
Link: CVE-2023-6966
Updated: 2024-08-02T08:50:06.854Z
Status : Modified
Published: 2024-06-06T02:15:52.607
Modified: 2024-11-21T08:44:56.403
Link: CVE-2023-6966
No data.
OpenCVE Enrichment
No data.
EUVD