WordPress Webpushr Plugin <= 4.34.0 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-35041
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 November 2023
What is CVE-2023-35041?
This vulnerability is a Cross-Site Request Forgery (CSRF) issue that can lead to Local File Inclusion (LFI) in versions of the Webpushr Web Push Notifications plugin up to 4.34.0. An attacker can exploit this weakness to manipulate user actions without their consent, potentially allowing unauthorized access to sensitive files on the server.
Affected Version(s)
Web Push Notifications β Webpushr <= 4.34.0