CVE-2023-23992: WordPress AutomatorWP Plugin <= 2.5.0 is vulnerable to Cross Site Request Forgery (CSRF)
Published Feb 28, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in AutomatorWP plugin <= 2.5.0 leads to object delete.
Affected Software
1 affected component
AutomatorWP AutomatorWP WordPress<2.5.1
Remediation
Information
Update to 2.5.1 or a higher version.
Event History
Feb 28, 2023
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23992?
CVE-2023-23992 has been classified as a high-severity vulnerability due to its potential to allow unauthorized object deletion.
2
How do I fix CVE-2023-23992?
To fix CVE-2023-23992, upgrade the AutomatorWP plugin to version 2.5.1 or later.
3
Who is affected by CVE-2023-23992?
CVE-2023-23992 affects users of the AutomatorWP plugin versions 2.5.0 and earlier.
4
What type of vulnerability is CVE-2023-23992?
CVE-2023-23992 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What impact does CVE-2023-23992 have on web applications?
CVE-2023-23992 can lead to unauthorized actions being performed on behalf of authenticated users, potentially resulting in data loss.