CVE-2023-34373: WordPress Zephyr Project Manager Plugin <= 3.3.93 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jun 19, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions.
Affected Software
1 affected component
Zephyr Project Manager Project Zephyr Project Manager Wordpress<=3.3.93
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Zephyr Project Manager pluginto a version that resolves this vulnerability.Fixed in 3.3.94
Event History
Jun 19, 2023
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34373?
The severity of CVE-2023-34373 is rated as high with a CVSS score of 8.8.
2
How can I mitigate the CSRF vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions?
To mitigate the CSRF vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions, update to a version beyond 3.3.93 if available or apply any patches provided by the developer.