CVE-2023-28694: WordPress Wbcom Designs – BuddyPress Activity Social Share Plugin <= 3.5.0 is vulnerable to Cross Site Request Forgery (CSRF)
Published Nov 12, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Wbcom Designs Wbcom Designs – BuddyPress Activity Social Share plugin <= 3.5.0 versions.
Affected Software
1 affected component
Wbcomdesigns Buddypress Activity Social Share Wordpress<=3.5.0
Event History
Nov 12, 2023
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this WordPress plugin vulnerability?
The vulnerability ID is CVE-2023-28694.
2
What is the title of this WordPress plugin vulnerability?
The title of this vulnerability is 'WordPress Wbcom Designs – BuddyPress Activity Social Share Plugin <= 3.5.0 is vulnerable to Cross-Site Request Forgery (CSRF)'.
3
What is the severity level of this vulnerability?
The severity level of this vulnerability is high (8.8).
4
What is the affected software of this vulnerability?
The affected software is Wbcom Designs - BuddyPress Activity Social Share plugin version 3.5.0 and below.
5
How can I fix this vulnerability?
To fix this vulnerability, update Wbcom Designs - BuddyPress Activity Social Share plugin to version 3.5.1 or higher.