CVE-2023-23802: WordPress HT Easy GA4 ( Google Analytics 4 ) Plugin <= 1.0.6 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jun 15, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions.
Affected Software
1 affected component
HasThemes Ht Easy Ga4 \(google Analytics 4\) Wordpress<1.0.7
Remediation
Information
Update to 1.0.7 or a higher version.
Event History
Jun 15, 2023
CVE Published
via MITRE·12:03 PM
Data Sourced
via MITRE·12:03 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23802?
The severity of CVE-2023-23802 is high with a score of 8.8.
2
What is the affected software for CVE-2023-23802?
The affected software for CVE-2023-23802 is HasThemes HT Easy GA4 (Google Analytics 4) plugin version 1.0.6 and below.
3
What is the CWE for CVE-2023-23802?
The CWE for CVE-2023-23802 is CWE-352.
4
How can I fix the CSRF vulnerability in HasThemes HT Easy GA4?
To fix the CSRF vulnerability in HasThemes HT Easy GA4, update the plugin to version 1.0.7 or above.
5
Where can I find more information about CVE-2023-23802?
You can find more information about CVE-2023-23802 at the following link: [Patchstack - CVE-2023-23802](https://patchstack.com/database/vulnerability/ht-easy-google-analytics/wordpress-ht-easy-ga4-google-analytics-4-plugin-1-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve)