WordPress WOLF Plugin <= 1.0.7.1 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-46152

4.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
25 October 2023

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WOLF – WordPress Posts Bulk Editor and Manager Professional plugin, affecting versions up to 1.0.7.1. This flaw could allow attackers to perform unauthorized actions on behalf of users within the WordPress environment, potentially leading to the manipulation of posts and sensitive information. It is crucial for users to upgrade to the latest version and apply security best practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.7.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thiennv (Patchstack Alliance)
.