Cross-Site Request Forgery Vulnerability in Under Construction Plugin for WordPress
CVE-2023-0831
What is CVE-2023-0831?
The Under Construction plugin for WordPress has a security vulnerability that allows for Cross-Site Request Forgery (CSRF). This flaw arises from inadequate nonce validation in the dismiss_notice function as triggered by the admin_action_ucp_dismiss_notice action. When exploited, this vulnerability permits unauthenticated attackers to bypass notifications intended for site administrators by sending a manipulated request. Attackers can potentially mislead an administrator into taking actions that dismiss important plugin alerts, which could lead to oversight of critical updates or changes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Under Construction * <= 3.96
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved