🔐 CVE Alert

CVE-2023-4728

MEDIUM 4.3

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Missing Authorization on publish_lp()

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to change the LadiPage key (a key fully controlled by the attacker), enabling them to freely create new pages, including web pages that trigger stored XSS

CWE CWE-862
Vendor binhnguyenplus
Product ladiapp: landing page, popupx, marketing automation, affiliate marketing…
Published Mar 12, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for binhnguyenplus ladiapp: landing page, popupx, marketing automation, affiliate marketing…

Be the first to know when new medium vulnerabilities affecting binhnguyenplus ladiapp: landing page, popupx, marketing automation, affiliate marketing… are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

binhnguyenplus / LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…
0 ≤ 4.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/6dafc81c-f1be-422d-b34f-87f1956e8849?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ladipage/trunk/ladipage.php#L1992

Credits

GiongfNef