CVE-2023-0496: HT Event < 1.4.6 - Arbitrary Plugin Activation via CSRF
Published Mar 27, 2023
·Updated
The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Affected Software
1 affected component
HasThemes Ht Event Wordpress<1.4.6
Event History
Mar 27, 2023
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this HT Event WordPress plugin vulnerability?
The vulnerability ID of this HT Event WordPress plugin vulnerability is CVE-2023-0496.
2
What is the severity of CVE-2023-0496?
The severity of CVE-2023-0496 is medium with a score of 4.3.
3
How can attackers exploit CVE-2023-0496?
Attackers can exploit CVE-2023-0496 by performing a CSRF attack to make logged in admins activate arbitrary plugins present on the blog.
4
What is the affected software for CVE-2023-0496?
The affected software for CVE-2023-0496 is the HT Event WordPress plugin before version 1.4.6.
5
Is there a fix available for CVE-2023-0496?
Yes, the fix for CVE-2023-0496 is to update the HT Event WordPress plugin to version 1.4.6 or higher.