CVE-2023-1979

    Dashboard / Vulnerabilities / CVE-2023-1979

    CVE-2023-1979

    Published: 8 May 2023Last Modified: 12 Aug 2026

    Summary: Auth bypass in Web Stories for WordPress plugin

    Details: The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't have the ability to edit password protected stories. The vulnerability allowed users with said role to bypass this permission check when trying to duplicate the protected story in the plugin's own dashboard, giving them access to the seemingly protected content. We recommend upgrading to version 1.32 or beyond commit  ad49781c2a35c5c92ef704d4b621ab4e5cb77d68 https://github.com/GoogleForCreators/web-stories-wp/commit/ad49781c2a35c5c92ef704d4b621ab4e5cb77d68

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    url-v0.1.202303271448
    url-v0.1.202204141511
    url-v0.1.202203150806
    url-v0.1.202208291229
    url-v0.1.202302061326
    url-v0.1.202212071230
    url-v0.1.202203010801
    url-v0.1.202208081316
    url-v0.1.202206271222
    url-v0.1.202203241635
    url-v0.1.202207041221
    url-v0.1.202212191259
    url-v0.1.202211151052
    url-v0.1.202301231653
    url-v0.1.202208151234
    url-v0.1.202206201534
    url-v0.1.202205021257

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-1979 | CVE-DB