Junglewise Threat Intelligence

CVE-2023-40200: Essential Plugin WP Logo Showcase Responsive Slider and Carousel auth bypass

CVE-2023-40200 · Severity: medium · CVSS 5.3 · Published 2026-06-11

Executive brief

A vulnerability exists in a popular WordPress plugin used to display logo sliders and carousels on websites. This flaw allows unauthorized individuals to bypass security checks and potentially modify settings or content that should be restricted to administrators. This could lead to unauthorized changes to the website's appearance or configuration, impacting the integrity of the site.

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-284 (Improper Access Control). It occurs because the plugin fails to properly validate authorization or check nonces for certain functions, allowing unauthenticated users to manipulate internal keys to perform actions intended for higher-privileged users. The attack can be executed remotely over the network without any user interaction. An attacker can exploit this to modify plugin-related data or settings. The issue is resolved in version 3.7.

Affected products

  • Essential Plugin WP Logo Showcase Responsive Slider and Carousel <= 3.6

Timeline

  • 2023-07-20: other: Reported by researcher Abdi Pranata
  • 2023-11-09: advisory: Initial Patchstack advisory published
  • 2026-06-11: disclosed: NVD publication date

References