CVE-2023-23659: WordPress MainWP Matomo Extension Plugin <= 4.0.4 is vulnerable to Cross Site Request Forgery (CSRF)
Published Feb 23, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions.
Affected Software
1 affected component
MainWP Motomo Motomo<4.0.5
Remediation
Information
Update to 4.0.5 or a higher version.
Event History
Feb 23, 2023
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23659?
The severity of CVE-2023-23659 is high with a CVSS score of 8.8.
2
How does CVE-2023-23659 affect MainWP Matomo Extension?
CVE-2023-23659 affects MainWP Matomo Extension versions <= 4.0.4.
3
What is Cross-Site Request Forgery (CSRF) vulnerability?
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into submitting a malicious request by leveraging their authenticated session.
4
How can I fix CVE-2023-23659?
To fix CVE-2023-23659, update MainWP Matomo Extension to version 4.0.5 or higher.
5
Where can I find more information about CVE-2023-23659?
You can find more information about CVE-2023-23659 at https://patchstack.com/database/vulnerability/mainwp-piwik-extension/wordpress-mainwp-matomo-extension-plugin-4-0-4-csrf-leading-to-plugin-settings-change-vulnerability?_s_id=cve