CVE-2023-0501: WP Insurance < 2.1.4 - Arbitrary Plugin Activation via CSRF
Published Mar 27, 2023
·Updated
The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Affected Software
1 affected component
HasThemes Wp Insurance Wordpress<2.1.4
Event History
Mar 27, 2023
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-0501.
2
What is the severity rating of CVE-2023-0501?
The severity rating of CVE-2023-0501 is medium (6.5).
3
What is the affected software for CVE-2023-0501?
The affected software for CVE-2023-0501 is the WP Insurance WordPress plugin before version 2.1.4.
4
What is the CWE ID for CVE-2023-0501?
The CWE ID for CVE-2023-0501 is CWE-352.
5
How can an attacker exploit CVE-2023-0501?
An attacker can exploit CVE-2023-0501 by performing a CSRF attack to make logged in admins activate arbitrary plugins present on the blog.