CVE-2023-35047: WordPress All Bootstrap Blocks Plugin <= 1.3.6 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jul 11, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in AREOI All Bootstrap Blocks plugin <= 1.3.6 versions.
Affected Software
1 affected component
AREOI All Bootstrap Blocks Wordpress<=1.3.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress All Bootstrap Blocks pluginto a version that resolves this vulnerability.Fixed in 1.3.7
Event History
Jul 11, 2023
CVE Published
via MITRE·11:14 AM
Data Sourced
via MITRE·11:14 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-35047?
CVE-2023-35047 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-35047?
To fix CVE-2023-35047, update the AREOI All Bootstrap Blocks plugin to a version newer than 1.3.6.
3
What versions of AREOI All Bootstrap Blocks are affected by CVE-2023-35047?
CVE-2023-35047 affects all versions of the AREOI All Bootstrap Blocks plugin up to and including version 1.3.6.
4
What type of attack does CVE-2023-35047 enable?
CVE-2023-35047 enables attackers to execute unauthorized actions on behalf of an authenticated user.
5
Is authentication required to exploit CVE-2023-35047?
Yes, exploiting CVE-2023-35047 typically requires that the victim is authenticated.