CVE-2023-22672: WordPress vSlider Multi Image Slider for WordPress Plugin <= 4.1.2 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jul 17, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions.
Affected Software
1 affected component
VibeThemes Vslider Wordpress<=4.1.2
Event History
Jul 17, 2023
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionSeverityWeakness
Data Sourced
11:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-22672?
The severity of CVE-2023-22672 is considered to be high due to its potential for exploitation via Cross-Site Request Forgery.
2
How do I fix CVE-2023-22672?
To fix CVE-2023-22672, it is recommended to update the Mr.Vibe vSlider Multi Image Slider plugin to version 4.1.3 or later.
3
Which versions of the plugin are affected by CVE-2023-22672?
Versions of the Mr.Vibe vSlider Multi Image Slider plugin up to and including 4.1.2 are affected by CVE-2023-22672.
4
What type of vulnerability is CVE-2023-22672?
CVE-2023-22672 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2023-22672 lead to data compromise?
Yes, CVE-2023-22672 can lead to unauthorized actions being performed on behalf of an authenticated user, potentially compromising user data.