AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-3063

HIGH · CVSS 8.8 EPSS 0.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-3063
Severity
HIGH
CVSS
8.8
EPSS
0.73%
WordPress

Original NVD Description

The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber privileges or above, to change user passwords and potentially take over administrator accounts.