WordPress CLUEVO LMS, E-Learning Platform Plugin <= 1.10.0 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-40607 
4.3MEDIUM
Key Information:
- Vendor
 WordPress
- Vendor
 - CVE Published:
 - 6 October 2023
 
What is CVE-2023-40607?
Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <=Â 1.10.0 versions.
Affected Version(s)
CLUEVO LMS, E-Learning Platform <= 1.10.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
 Low
Availability:
 None
Attack Vector:
Network
Attack Complexity:
 Low
Privileges Required:
 None
User Interaction:
 Required
Scope:
 Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Debangshu Kundu & Arpeet Rathi (Patchstack Alliance)