First published: Tue May 23 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
miniOrange WordPress Social Login and Register | <7.6.0 |
Update to 7.6.0 or a higher version
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2023-23706.
The severity of CVE-2023-23706 is high with a CVSS score of 8.8.
The affected software is the miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin versions up to 7.5.14.
The CWE ID for this vulnerability is CWE-352.
Yes, a patch is available for this vulnerability. Please refer to the reference link for more information.