CVE-2023-23899: WordPress Extensions For CF7 Plugin <= 2.0.8 is vulnerable to Cross Site Request Forgery (CSRF)
Published Feb 17, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Extensions For CF7 plugin <= 2.0.8 versions leads to arbitrary plugin activation.
Affected Software
1 affected component
HasThemes Extensions For Cf7 Wordpress<2.0.9
Remediation
Information
Update to 2.0.9 or a higher version.
Event History
Feb 17, 2023
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-23899?
CVE-2023-23899 is a Cross-Site Request Forgery (CSRF) vulnerability in the HasThemes Extensions For CF7 plugin <= 2.0.8 versions.
2
What is the severity of CVE-2023-23899?
The severity of CVE-2023-23899 is medium with a CVSS score of 4.3.
3
How does CVE-2023-23899 affect software?
CVE-2023-23899 affects the HasThemes Extensions For CF7 plugin versions up to and including 2.0.8.
4
What is the impact of CVE-2023-23899?
CVE-2023-23899 allows for arbitrary plugin activation.
5
Is there a fix for CVE-2023-23899?
Yes, updating to a version greater than 2.0.8 of the HasThemes Extensions For CF7 plugin will fix CVE-2023-23899.