WordPress Perfmatters Plugin <= 2.1.6 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-47875

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
30 November 2023

Summary

A Cross-Site Request Forgery (CSRF) vulnerability in Perfmatters allows attackers to perform unauthorized actions on behalf of authenticated users. This issue can lead to significant security ramifications, enabling malicious actors to exploit the trust a web application has in a user's browser. The affected versions are from the initial release up to and including version 2.1.6, emphasizing the need for immediate updates or patches to prevent potential exploits.

Affected Version(s)

Perfmatters <= 2.1.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave Jong (Patchstack)
.