CVE-2023-34025: WordPress LWS Hide Login plugin <= 2.1.6 - Cross Site Request Forgery (CSRF) vulnerability
Published Nov 9, 2023
·Updated
A vulnerability in Aurélien LWS LWS Hide Login lws-hide-login.This issue affects LWS Hide Login: from n/a through <= 2.1.6.
Affected Software
1 affected component
LWS Lws Hide Login Wordpress<=2.1.6
Remediation
Information
Update to 2.1.7 or a higher version.
Event History
Nov 9, 2023
CVE Published
via MITRE·08:29 PM
Data Sourced
via MITRE·08:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34025?
CVE-2023-34025 is a Cross-Site Request Forgery (CSRF) vulnerability found in the LWS Hide Login plugin for WordPress versions up to 2.1.6.
2
How severe is CVE-2023-34025?
CVE-2023-34025 has a severity rating of 8.8, which is considered high.
3
How does CVE-2023-34025 affect my website?
CVE-2023-34025 allows an attacker to perform unauthorized actions on behalf of a logged-in user, potentially compromising the security and integrity of your website.
4
Is my version of the LWS Hide Login plugin affected by CVE-2023-34025?
If you are using LWS Hide Login plugin version 2.1.6 or below, your website is vulnerable to CVE-2023-34025.
5
How can I fix CVE-2023-34025?
To fix CVE-2023-34025, you should update the LWS Hide Login plugin to a version that is not vulnerable, such as version 2.1.7 or later.