First published: Mon Mar 27 2023(Updated: )
The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hasthemes Quickswish | <1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the QuickSwish WordPress plugin is CVE-2023-0499.
The severity of CVE-2023-0499 is medium with a severity value of 4.3.
CVE-2023-0499 affects the QuickSwish WordPress plugin by not having a CSRF check when activating plugins, allowing attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack.
To fix CVE-2023-0499, make sure to update the QuickSwish WordPress plugin to version 1.1.0 or later, which includes the CSRF check when activating plugins.
The CWE ID associated with CVE-2023-0499 is CWE-352.