CVE-2023-26518: WordPress WP TFeed Plugin <= 1.6.9 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes WP TFeed plugin <= 1.6.9 versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26518 vulnerability?
CVE-2023-26518 is a Cross-Site Request Forgery (CSRF) vulnerability in the AccessPress Themes WP TFeed plugin <= 1.6.9 for WordPress.
How severe is CVE-2023-26518?
CVE-2023-26518 has a severity score of 8.8 (high).
How does CVE-2023-26518 affect users?
CVE-2023-26518 allows an attacker to perform unauthorized actions on behalf of a user, potentially leading to account compromise or other malicious activities.
Is there a fix available for CVE-2023-26518?
Yes, upgrading to a version higher than 1.6.9 of the AccessPress Themes WP TFeed plugin will fix the vulnerability.
Where can I find more information about CVE-2023-26518?
You can find more information about CVE-2023-26518 at the following reference link: [https://patchstack.com/database/vulnerability/accesspress-twitter-feed/wordpress-wp-tfeed-plugin-1-6-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/accesspress-twitter-feed/wordpress-wp-tfeed-plugin-1-6-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve).