CVE-2023-35096: WordPress myCred Plugin <= 2.5 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in myCred plugin <= 2.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress myCred pluginto a version that resolves this vulnerability.Fixed in 2.5.1
Event History
Frequently Asked Questions
What is CVE-2023-35096?
CVE-2023-35096 is a Cross-Site Request Forgery (CSRF) vulnerability in the myCred plugin version 2.5 or below for WordPress.
How severe is CVE-2023-35096?
CVE-2023-35096 has a severity score of 8.8, which is considered high.
What is the affected software for CVE-2023-35096?
The affected software for CVE-2023-35096 is the myCred plugin version 2.5 or below for WordPress.
How can I fix CVE-2023-35096?
To fix CVE-2023-35096, you should update the myCred plugin to a version higher than 2.5.
Where can I find more information about CVE-2023-35096?
You can find more information about CVE-2023-35096 in the Patchstack vulnerability database at https://patchstack.com/database/vulnerability/mycred/wordpress-mycred-plugin-2-5-cross-site-request-forgery-csrf.