WordPress Perfmatters Plugin <= 2.1.6 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-47875
8.8HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability in Perfmatters allows attackers to perform unauthorized actions on behalf of authenticated users. This issue can lead to significant security ramifications, enabling malicious actors to exploit the trust a web application has in a user's browser. The affected versions are from the initial release up to and including version 2.1.6, emphasizing the need for immediate updates or patches to prevent potential exploits.
Affected Version(s)
Perfmatters <= 2.1.6
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dave Jong (Patchstack)