First published: Fri Jun 09 2023(Updated: )
The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the install_weglot function called via the admin_action_install_weglot action. This makes it possible for unauthenticated attackers to perform an unauthorized install of the Weglot Translate plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Webfactoryltd Under Construction | <=3.96 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0832 is classified as a high severity vulnerability due to its potential exploitation through cross-site request forgery.
To fix CVE-2023-0832, update the Under Construction plugin to version 3.97 or later, which includes proper nonce validation.
CVE-2023-0832 affects all versions of the Under Construction plugin for WordPress up to and including 3.96.
CVE-2023-0832 is a Cross-Site Request Forgery vulnerability that arises from improper nonce validation.
Websites using versions of the Under Construction plugin for WordPress up to 3.96 are impacted by CVE-2023-0832.