CVE-2023-23787: WordPress Premmerce Redirect Manager Plugin <= 1.0.9 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jul 10, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions.
Affected Software
1 affected component
Premmerce Redirect Manager Wordpress<=1.0.9
Event History
Jul 10, 2023
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23787?
CVE-2023-23787 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to unauthorized actions being performed on behalf of authenticated users.
2
How do I fix CVE-2023-23787?
To fix CVE-2023-23787, update the Premmerce Redirect Manager plugin to version 1.0.10 or later.
3
What versions are affected by CVE-2023-23787?
CVE-2023-23787 affects all versions of the Premmerce Redirect Manager plugin up to and including version 1.0.9.
4
Can CVE-2023-23787 allow attackers to exploit user sessions?
Yes, attackers can exploit CVE-2023-23787 to perform actions on behalf of users without their consent.
5
Is there any temporary mitigation for CVE-2023-23787 before updating?
A temporary mitigation for CVE-2023-23787 includes disabling the plugin until it can be updated.