CVE-2023-34178: WordPress Groundhogg plugin <= 2.7.11 - Cross Site Request Forgery (CSRF)
Published Nov 9, 2023
·Updated
A vulnerability in Adrian Tobey Groundhogg groundhogg.This issue affects Groundhogg: from n/a through <= 2.7.11.
Affected Software
1 affected component
Groundhogg Groundhogg WordPress<2.7.11.1
Remediation
Information
Update to 2.7.11.1 or a higher version.
Event History
Nov 9, 2023
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34178?
The severity of CVE-2023-34178 is high (8.8).
2
What is the vulnerability in WordPress Groundhogg Plugin?
The vulnerability in WordPress Groundhogg Plugin is a Cross-Site Request Forgery (CSRF).
3
Which version of Groundhogg Plugin is affected by CVE-2023-34178?
Groundhogg Plugin <= 2.7.11 is affected by CVE-2023-34178.
4
How can I fix the vulnerability in WordPress Groundhogg Plugin?
To fix the vulnerability, update Groundhogg Plugin to version 2.7.11.1 or later.
5
Where can I find more information about CVE-2023-34178?
You can find more information about CVE-2023-34178 at this link: [WordPress Groundhogg Plugin <= 2.7.11 Cross-Site Request Forgery (CSRF)](https://patchstack.com/database/vulnerability/groundhogg/wordpress-groundhogg-plugin-2-7-10-3-cross-site-request-forgery-csrf)