CVE-2023-1086: Preview Link Generator < 1.0.4 - Arbitrary Plugin Activation via CSRF
Published Mar 27, 2023
·Updated
The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Affected Software
1 affected component
HasThemes Preview Link Generator Wordpress<1.0.4
Event History
Mar 27, 2023
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the Preview Link Generator WordPress plugin?
The vulnerability ID of the Preview Link Generator WordPress plugin is CVE-2023-1086.
2
What is the severity rating of CVE-2023-1086?
CVE-2023-1086 has a severity rating of 4.3 (medium).
3
How can an attacker exploit CVE-2023-1086?
An attacker can exploit CVE-2023-1086 by performing a CSRF attack to make logged-in admins activate arbitrary plugins.
4
What software versions are affected by CVE-2023-1086?
The Preview Link Generator WordPress plugin versions up to 1.0.4 are affected by CVE-2023-1086.
5
Is there a fix available for CVE-2023-1086?
Yes, upgrading to version 1.0.4 of the Preview Link Generator WordPress plugin fixes CVE-2023-1086.