WordPress WP Report Post Plugin <= 2.1.2 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-34171

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
9 November 2023

Summary

The Alex Raven WP Report Post plugin versions up to 2.1.2 are vulnerable to a Cross-Site Request Forgery (CSRF) attack. This type of vulnerability allows attackers to trick a user into executing unwanted actions on a web application in which they're authenticated. Exploitation of CSRF can lead to unauthorized actions being performed without the user's consent, potentially compromising the security of affected WordPress sites. It is imperative for site administrators to ensure they are running an updated version of the plugin to mitigate this risk.

Affected Version(s)

WP Report Post <= 2.1.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.