WordPress WOLF Plugin <= 1.0.7.1 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-46152
4.3MEDIUM
Key Information:
- Vendor
- Realmag777
- Status
- Wolf – WordPress Posts Bulk Editor And Manager Professional
- Vendor
- CVE Published:
- 25 October 2023
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WOLF – WordPress Posts Bulk Editor and Manager Professional plugin, affecting versions up to 1.0.7.1. This flaw could allow attackers to perform unauthorized actions on behalf of users within the WordPress environment, potentially leading to the manipulation of posts and sensitive information. It is crucial for users to upgrade to the latest version and apply security best practices to mitigate the risks associated with this vulnerability.
Affected Version(s)
WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.7.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
thiennv (Patchstack Alliance)