First published: Tue Jul 11 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.5 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-company Button Generator | <=2.3.5 |
Update to 2.3.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25443 is a Cross-Site Request Forgery (CSRF) vulnerability found in Wow-Company Button Generator plugin version 2.3.5 and below.
If you are using Wow-Company Button Generator plugin version 2.3.5 or below, your website may be vulnerable to Cross-Site Request Forgery attacks.
CVE-2023-25443 has a severity rating of 6.5 (Medium).
To fix CVE-2023-25443, you should update the Wow-Company Button Generator plugin to a version higher than 2.3.5.
You can find more information about CVE-2023-25443 [here](https://patchstack.com/database/vulnerability/button-generation/wordpress-button-generator-plugin-2-3-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve).