Cross-Site Request Forgery in GMAce Plugin for WordPress
CVE-2023-1509
8.8HIGH
What is CVE-2023-1509?
The GMAce plugin for WordPress, in versions up to and including 1.5.2, is susceptible to Cross-Site Request Forgery due to a failure in nonce validation within the gmace_manager_server function. This vulnerability allows unauthorized attackers to exploit this oversight, potentially modifying arbitrary files and executing remote code by tricking a site administrator into executing a malicious request. Administrators should apply the necessary updates to protect their sites from such forged actions.
Affected Version(s)
GMAce * <= 1.5.2