WordPress WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) Plugin <= 7.5.14 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-23706
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 May 2023
What is CVE-2023-23706?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the miniOrange WordPress Social Login and Register plugin, affecting versions up to 7.5.14. This flaw could allow attackers to trick users into executing unwanted actions on their logged-in accounts without their consent. Website owners utilizing this plugin are urged to apply the latest updates to mitigate potential security risks.
Affected Version(s)
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14