CVE-2023-25463: WordPress wp tell a friend popup form Plugin <= 7.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published Oct 3, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy WP tell a friend popup form plugin <= 7.1 versions.
Affected Software
1 affected component
gopiplus Wp-tell-a-friend-popup-form Wordpress<=7.1
Event History
Oct 3, 2023
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25463?
CVE-2023-25463 is a Cross-Site Request Forgery (CSRF) vulnerability found in Gopi Ramasamy WP tell a friend popup form plugin versions up to 7.1.
2
How severe is CVE-2023-25463?
CVE-2023-25463 has a severity value of 8.8, which is considered high.
3
Which software versions are affected by CVE-2023-25463?
Gopi Ramasamy WP tell a friend popup form plugin versions up to 7.1 are affected by CVE-2023-25463.
4
What is the CWE classification of CVE-2023-25463?
CVE-2023-25463 is classified under CWE-352 (Cross-Site Request Forgery).
5
How can I fix CVE-2023-25463?
To fix CVE-2023-25463, it is recommended to update the Gopi Ramasamy WP tell a friend popup form plugin to a version above 7.1.