CVE-2023-0495: HT Slider For Elementor < 1.4.0 - Arbitrary Plugin Activation via CSRF
Published Mar 27, 2023
·Updated
The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Affected Software
1 affected component
HasThemes Ht Slider For Elementor Wordpress<1.4.0
Event History
Mar 27, 2023
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-0495.
2
What is the severity of CVE-2023-0495?
The severity of CVE-2023-0495 is medium (4.3).
3
What is the affected software of CVE-2023-0495?
The affected software of CVE-2023-0495 is the HT Slider For Elementor WordPress plugin version up to 1.4.0.
4
What is the CWE category of CVE-2023-0495?
The CWE category of CVE-2023-0495 is CWE-352.
5
How can attackers exploit CVE-2023-0495?
Attackers can exploit CVE-2023-0495 by making logged in admins activate arbitrary plugins on the blog via a CSRF attack.