WordPress SendPress Newsletters Plugin <= 1.22.3.31 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-41730
8.8HIGH
What is CVE-2023-41730?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SendPress Newsletters plugin for WordPress, specifically in versions 1.22.3.31 and earlier. This vulnerability could allow an attacker to perform unauthorized actions on behalf of logged-in users without their consent, potentially compromising the integrity of user accounts and sensitive information. Users are encouraged to update to the latest version of the plugin to mitigate the risk of exploitation.
Affected Version(s)
SendPress Newsletters <= 1.22.3.31