CVE-2023-33931: WordPress YouTube Playlist Player Plugin <= 4.6.4 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.4 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress YouTube Playlist Player Pluginto a version that resolves this vulnerability.Fixed in 4.6.5
Event History
Frequently Asked Questions
What is CVE-2023-33931?
CVE-2023-33931 is a Cross-Site Request Forgery (CSRF) vulnerability found in the Ciprian Popescu YouTube Playlist Player plugin.
How severe is CVE-2023-33931?
CVE-2023-33931 has a severity rating of 8.8, which is considered high.
Which software versions are affected by CVE-2023-33931?
CVE-2023-33931 affects versions up to and including 4.6.4 of the Ciprian Popescu YouTube Playlist Player plugin for WordPress.
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2023-33931.
How can I fix CVE-2023-33931?
To fix CVE-2023-33931, update the Ciprian Popescu YouTube Playlist Player plugin to version 4.6.5 or higher.