CVE-2023-30478: WordPress Newsletters plugin <= 4.8.8 - Cross Site Request Forgery (CSRF) vulnerability
A vulnerability in Tribulant Software Newsletters newsletters-lite.This issue affects Newsletters: from n/a through <= 4.8.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-30478?
CVE-2023-30478 refers to a Cross-Site Request Forgery (CSRF) vulnerability in the Tribulant Newsletters plugin version 4.8.8 and below for WordPress.
How severe is CVE-2023-30478?
CVE-2023-30478 has a severity rating of 8.8 (high).
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is a type of attack where an attacker tricks a victim into performing unwanted actions on a trusted website, without their knowledge or consent.
How can I fix the CVE-2023-30478 vulnerability?
To fix the CVE-2023-30478 vulnerability, you should update your Tribulant Newsletters plugin to version 4.8.9 or higher.
Where can I find more information about CVE-2023-30478?
You can find more information about CVE-2023-30478 at this link: [https://patchstack.com/database/vulnerability/newsletters-lite/wordpress-newsletters-plugin-4-8-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/newsletters-lite/wordpress-newsletters-plugin-4-8-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve)