CVE-2023-35774: WordPress LWS Tools Plugin <= 2.4.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jul 11, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.4.1 versions.
Affected Software
1 affected component
LWS Lws Tools Wordpress<2.4.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/lws-tools-pluginto a version that resolves this vulnerability.Fixed in 2.4.2
Event History
Jul 11, 2023
CVE Published
via MITRE·08:05 AM
Data Sourced
via MITRE·08:05 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-35774?
CVE-2023-35774 is a Cross-Site Request Forgery (CSRF) vulnerability in the LWS LWS Tools plugin version 2.4.1 and below.
2
How severe is CVE-2023-35774?
CVE-2023-35774 has a severity rating of 8.8 (high).
3
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack that tricks an authenticated user into executing unwanted actions on a web application.
4
Which software versions are affected by CVE-2023-35774?
CVE-2023-35774 affects LWS LWS Tools plugin versions up to and including 2.4.1.
5
Is there a fix for CVE-2023-35774?
Yes, the LWS LWS Tools plugin version 2.4.2 and above includes a fix for CVE-2023-35774.