CVE-2023-28498: WordPress Hotel Booking Lite Plugin <= 4.6.0 is vulnerable to Cross Site Request Forgery (CSRF)
Published Nov 12, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions.
Affected Software
1 affected component
MotoPress Hotel Booking Lite Wordpress<=4.6.0
Remediation
Information
Update to 4.7.0 or a higher version.
Event History
Nov 12, 2023
CVE Published
09:57 PM
Data Sourced
09:57 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-28498?
CVE-2023-28498 is a Cross Site Request Forgery (CSRF) vulnerability found in the WordPress Hotel Booking Lite plugin version 4.6.0 and earlier.
2
How severe is CVE-2023-28498?
CVE-2023-28498 has a severity rating of 8.8 (high).
3
Which software versions are affected by CVE-2023-28498?
The Motopress Hotel Booking Lite plugin version <= 4.6.0 is affected by CVE-2023-28498.
4
What is Cross Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they are authenticated.
5
How can I fix CVE-2023-28498?
To fix CVE-2023-28498, upgrade the WordPress Hotel Booking Lite plugin to version 4.6.1 or later.