CVE-2023-32123: WordPress The7 Theme <= 11.7.3 is vulnerable to Cross Site Request Forgery (CSRF)
Published Nov 13, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Dream-Theme The7 allows Stored XSS.This issue affects The7: from n/a through 11.7.3.
Affected Software
1 affected component
Dream-Theme The7 Wordpress<=11.7.3
Remediation
Information
Update to 11.7.3.1 or a higher version.
Event History
Nov 13, 2023
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-32123.
2
What is the severity of CVE-2023-32123?
The severity of CVE-2023-32123 is high (7.1).
3
What is the affected software?
The affected software is Dream-Theme The7 version up to and including 11.7.3.
4
What does the vulnerability allow?
The vulnerability allows for Cross-Site Request Forgery (CSRF) and Stored XSS.
5
How can I fix CVE-2023-32123?
To fix CVE-2023-32123, update Dream-Theme The7 to the latest version available.