CVE-2023-5235: Kutethemes Ovic Responsive Wpbakery
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks.
Affected products
- Kutethemes Ovic Responsive Wpbakery: before 1.2.9 (fixed in 1.2.9)
Published 2024-01-08. Last modified 2026-06-17.