CVE-2023-0502: WP News <= 1.1.9 - Arbitrary Plugin Activation via CSRF
Published Mar 27, 2023
·Updated
The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Affected Software
1 affected component
HasThemes Wp News Wordpress<=1.1.9
Event History
Mar 27, 2023
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-0502.
2
What is the severity of CVE-2023-0502?
The severity of CVE-2023-0502 is medium, with a severity value of 6.5.
3
How does CVE-2023-0502 affect the WP News WordPress plugin?
CVE-2023-0502 affects the WP News WordPress plugin version 1.1.9.
4
What is the impact of CVE-2023-0502?
CVE-2023-0502 allows attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack.
5
Is there a fix for CVE-2023-0502?
At the moment, there is no known fix for CVE-2023-0502. It is recommended to update to the latest version of the WP News WordPress plugin when it becomes available.