CVE-2023-48753: 10up Elasticpress

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Access: from n/a through 7.4.1.

Affected products

  • 10up Elasticpress: from 1.0, up to and including 7.4.1
  • 10up Restricted Site Access: up to and including 7.4.1

Published 2024-06-04. Last modified 2026-06-17.