Cross-Site Request Forgery Vulnerability in Short URL Plugin for WordPress

CVE-2023-1604

4.7MEDIUM

Key Information:

Vendor
Kaizencoders
Status
Short Url
Vendor
CVE Published:
17 August 2024

Summary

The Short URL plugin for WordPress possesses a vulnerability linked to inadequate nonce validation within the configuration_page function. This flaw allows unauthorized attackers to perform Cross-Site Request Forgery (CSRF) attacks. An attacker can exploit this weakness by luring a site administrator into clicking a manipulated link. Once successful, the attacker gains the ability to add or import redirects, including comments that may contain harmful cross-site scripting code, further compromising the security of the affected WordPress site.

Affected Version(s)

Short URL * <= 1.6.8

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Etan Imanol Castro Aldrete
.