Fusion Builder CSRF Vulnerability Affects Versions n/a through 3.11.1
CVE-2023-39311

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
27 March 2024

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeFusion Fusion Builder, impacting versions from an unspecified point up to and including 3.11.1. This security flaw allows an attacker to trick a user into executing unwanted actions on a web application in which they are authenticated. If exploited, the vulnerability could lead to unauthorized access or data manipulation, posing significant security risks to both the application and its users. Proper validation and implementation of CSRF tokens are essential for mitigating this flaw.

Affected Version(s)

Fusion Builder <= 3.11.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.