CVE-2023-0500: WP Film Studio < 1.3.5 - Arbitrary Plugin Activation via CSRF
The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability with CVE-2023-0500?
The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack.
Is there a known fix for CVE-2023-0500?
The fix for CVE-2023-0500 is to update the WP Film Studio WordPress plugin to version 1.3.5 or later.
What is the severity of CVE-2023-0500?
CVE-2023-0500 has a severity rating of medium.
How can attackers exploit CVE-2023-0500?
Attackers can exploit CVE-2023-0500 by performing a CSRF attack to make logged in admins activate arbitrary plugins on the blog.
Where can I find more information about CVE-2023-0500?
You can find more information about CVE-2023-0500 at the following reference link: [https://wpscan.com/vulnerability/95a6a11e-da5d-4fac-aff6-a3f7624682b7](https://wpscan.com/vulnerability/95a6a11e-da5d-4fac-aff6-a3f7624682b7)