CVE-2023-25968: WordPress Client Portal – Private user pages and login Plugin <= 1.1.8 is vulnerable to Cross Site Request Forgery (CSRF)
Published Mar 15, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin <= 1.1.8 versions.
Affected Software
1 affected component
Cozmoslabs Client Portal Wordpress<1.1.9
Remediation
Information
Update to 1.1.9 or a higher version.
Event History
Mar 15, 2023
CVE Published
via MITRE·10:20 AM
Data Sourced
via MITRE·10:20 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2023-25968.
2
What is the severity of CVE-2023-25968?
The severity of CVE-2023-25968 is high with a severity value of 8.8.
3
What is the affected software for CVE-2023-25968?
The affected software for CVE-2023-25968 is Cozmoslabs Madalin Ungureanu Antohe Cristian Client Portal - Private user pages and login plugin <= 1.1.8 versions.
4
How can I fix CVE-2023-25968?
To fix CVE-2023-25968, upgrade the Cozmoslabs Madalin Ungureanu Antohe Cristian Client Portal - Private user pages and login plugin to version 1.1.9 or higher.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-25968?
The CWE ID for CVE-2023-25968 is 352.