CVE-2023-35781: WordPress LWS Cleaner Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in LWS Cleaner plugin <= 2.3.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress LWS Cleaner pluginto a version that resolves this vulnerability.Fixed in 2.3.1
Event History
Frequently Asked Questions
What is CVE-2023-35781?
CVE-2023-35781 is a Cross-Site Request Forgery (CSRF) vulnerability in the LWS Cleaner plugin version 2.3.0 and below for WordPress.
What is the severity of CVE-2023-35781?
The severity of CVE-2023-35781 is rated as high with a CVSS score of 8.8.
How does CVE-2023-35781 affect the LWS Cleaner plugin?
CVE-2023-35781 affects the LWS Cleaner plugin version 2.3.0 and below, allowing attackers to perform Cross-Site Request Forgery (CSRF) attacks.
How can I fix CVE-2023-35781?
To fix CVE-2023-35781, update the LWS Cleaner plugin to version 2.3.1 or above.
Where can I find more information about CVE-2023-35781?
You can find more information about CVE-2023-35781 at this [link](https://patchstack.com/database/vulnerability/lws-cleaner/wordpress-lws-cleaner-plugin-2-3-0-multiple-cross-site-request-forgery-csrf-vulnerability?_s_id=cve).