CVE-2023-23797: WordPress Auto YouTube Importer Plugin <= 1.0.3 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 22, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <= 1.0.3 versions.
Affected Software
1 affected component
SecondLineThemes Auto Youtube Importer Wordpress<1.0.4
Remediation
Information
Update to 1.0.4 or a higher version.
Event History
May 22, 2023
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-23797?
CVE-2023-23797 is a Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin version 1.0.3 and below.
2
How severe is CVE-2023-23797?
CVE-2023-23797 has a severity rating of 8.8 (high).
3
How does CVE-2023-23797 affect the SecondLineThemes Auto YouTube Importer plugin?
CVE-2023-23797 affects SecondLineThemes Auto YouTube Importer plugin version 1.0.3 and below, allowing for potential Cross-Site Request Forgery (CSRF) attacks.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-23797?
The CWE ID for CVE-2023-23797 is 352.
5
How can I fix CVE-2023-23797?
To fix CVE-2023-23797, update the SecondLineThemes Auto YouTube Importer plugin to version 1.0.4 or above.