CVE-2023-23706: WordPress WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) Plugin <= 7.5.14 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 23, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
Affected Software
1 affected component
miniOrange Wordpress Social Login And Register \(discord\, Google\, Twitter\, Linkedin\) Wordpress<7.6.0
Remediation
Information
Update to 7.6.0 or a higher version
Event History
May 23, 2023
CVE Published
via MITRE·12:41 PM
Data Sourced
via MITRE·12:41 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2023-23706.
2
What is the severity of CVE-2023-23706?
The severity of CVE-2023-23706 is high with a CVSS score of 8.8.
3
What is the affected software?
The affected software is the miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin versions up to 7.5.14.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-352.
5
Is there a patch or fix available for this vulnerability?
Yes, a patch is available for this vulnerability. Please refer to the reference link for more information.