First published: Sat Nov 18 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Tomas | Docs | FAQ | Premium Support WordPress Tooltips.This issue affects WordPress Tooltips: from n/a through 8.2.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tooltips Wordpress Tooltips | <=8.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25985 is a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Tooltips Plugin <= 8.2.5.
CVE-2023-25985 has a severity rating of 8.8, which is considered high.
CVE-2023-25985 affects WordPress Tooltips versions from n/a through 8.2.5.
Cross-Site Request Forgery (CSRF) is a type of attack that tricks the victim into performing an unwanted action on a trusted site.
Yes, a fix for CVE-2023-25985 has been provided by the WordPress Tooltips Plugin. It is recommended to update to the latest version (8.2.6 or higher) to mitigate the vulnerability.