CVE-2023-23714: WordPress Uncanny Toolkit for LearnDash Plugin <= 3.6.4.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 26, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash plugin <= 3.6.4.1 versions.
Affected Software
1 affected component
Uncannyowl Uncanny Toolkit For Learndash Wordpress<=3.6.4.1
Remediation
Information
Update to 3.6.4.2 or a higher version.
Event History
May 26, 2023
CVE Published
via MITRE·11:01 AM
Data Sourced
via MITRE·11:01 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-23714?
CVE-2023-23714 is a Cross-Site Request Forgery (CSRF) vulnerability in the Uncanny Owl Uncanny Toolkit for LearnDash plugin.
2
What is the severity of CVE-2023-23714?
CVE-2023-23714 has a severity value of 8.8, which is considered high.
3
How does CVE-2023-23714 affect the Uncanny Toolkit for LearnDash plugin?
CVE-2023-23714 affects Uncanny Toolkit for LearnDash plugin versions up to and including 3.6.4.1.
4
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into submitting a malicious request.
5
What is the Common Weakness Enumeration (CWE) of CVE-2023-23714?
The Common Weakness Enumeration (CWE) of CVE-2023-23714 is CWE-352.