CVE-2023-27453: WordPress LWS Tools Plugin <= 2.3.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published Nov 22, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.3.1 versions.
Affected Software
1 affected component
LWS Lws Tools Wordpress<=2.3.1
Remediation
Information
Update to 2.4 or a higher version.
Event History
Nov 22, 2023
CVE Published
01:48 PM
Data Sourced
01:48 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-27453?
CVE-2023-27453 is a Cross-Site Request Forgery (CSRF) vulnerability found in the LWS Tools plugin for WordPress version 2.3.1 and below.
2
How severe is CVE-2023-27453?
CVE-2023-27453 has a severity rating of 8.8 (high).
3
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into performing unwanted actions on a trusted website.
4
Which software versions are affected by CVE-2023-27453?
CVE-2023-27453 affects LWS Tools plugin for WordPress versions up to and including 2.3.1.
5
How can I fix CVE-2023-27453?
To fix CVE-2023-27453, update the LWS Tools plugin for WordPress to a version higher than 2.3.1.