CVE-2023-40200 PUBLISHED

WordPress WP Logo Showcase Responsive Slider and Carousel plugin <= 3.6 - Broken Access Control vulnerability

Assigner: Patchstack
Reserved: 10.08.2023 Published: 11.06.2026 Updated: 11.06.2026

Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects WP Logo Showcase Responsive Slider and Carousel: from n/a through 3.6.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor Essential Plugin
Product WP Logo Showcase Responsive Slider and Carousel
Versions Default: unaffected
  • affected from n/a to 3.6 (incl.)

Solutions

Update the WordPress WP Logo Showcase Responsive Slider and Carousel plugin to the latest available version (at least 3.7).

Credits

  • Abdi Pranata | Patchstack Bug Bounty Progran finder

References

Problem Types

  • CWE-639 Authorization bypass through User-Controlled key CWE

Impacts

  • CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels