WordPress Original texts Yandex WebMaster Plugin <= 1.18 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-46775

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2023

What is CVE-2023-46775?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Djo Original Texts Yandex WebMaster Plugin for WordPress. This flaw allows an attacker to trick users into performing unwanted actions on behalf of a legitimate user, potentially compromising the security of their accounts and website operations. It is crucial for users of versions 1.18 and below to update their plugins promptly to safeguard against potential exploitation.

Affected Version(s)

Original texts Yandex WebMaster <= 1.18

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.