CVE-2023-33313: WordPress WIP Custom Login Plugin <= 1.2.9 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 28, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions.
Affected Software
1 affected component
ThemeinProgress Wip Custom Login Wordpress<1.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ThemeinProgress WIP Custom Login pluginto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
May 28, 2023
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-33313?
CVE-2023-33313 is a Cross-Site Request Forgery (CSRF) vulnerability found in the ThemeinProgress WIP Custom Login plugin version 1.2.9 and lower.
2
How severe is CVE-2023-33313?
CVE-2023-33313 has a severity rating of 8.8, which is considered high.
3
What software versions are affected by CVE-2023-33313?
CVE-2023-33313 affects ThemeinProgress WIP Custom Login plugin versions up to and including 1.2.9.
4
How can I fix CVE-2023-33313?
To fix CVE-2023-33313, you should update the ThemeinProgress WIP Custom Login plugin to version 1.3.0 or higher.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-33313?
The CWE ID for CVE-2023-33313 is 352.