CVE-2023-28495: WordPress WP Shortcode by MyThemeShop Plugin <= 1.4.16 is vulnerable to Cross Site Request Forgery (CSRF)
Published Nov 12, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions.
Affected Software
1 affected component
MyThemeShop Wp Shortcode Wordpress<=1.4.16
Remediation
Information
Update to 1.4.17 or a higher version.
Event History
Nov 12, 2023
CVE Published
10:07 PM
Data Sourced
10:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-28495?
CVE-2023-28495 is a Cross-Site Request Forgery (CSRF) vulnerability in the MyThemeShop WP Shortcode plugin version <= 1.4.16 for WordPress.
2
How severe is CVE-2023-28495?
CVE-2023-28495 has a severity rating of 8.8, which is considered high.
3
What software versions are affected by CVE-2023-28495?
CVE-2023-28495 affects MyThemeShop WP Shortcode plugin version <= 1.4.16 for WordPress.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-28495?
The Common Weakness Enumeration (CWE) ID for CVE-2023-28495 is CWE-352.
5
How can I fix CVE-2023-28495?
To fix CVE-2023-28495, update MyThemeShop WP Shortcode plugin to a version higher than 1.4.16.