CVE-2023-36682: WordPress Schema Pro Plugin <= 2.7.7 is vulnerable to Cross Site Request Forgery (CSRF)
Published Nov 30, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7.
Affected Software
1 affected component
Brainstormforce Schema Wordpress<2.7.8
Remediation
Information
Update to 2.7.8 or a higher version.
Event History
Nov 30, 2023
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-36682.
2
What is the title of this vulnerability?
The title of this vulnerability is 'WordPress Schema Pro Plugin <= 2.7.7 is vulnerable to Cross-Site Request Forgery (CSRF)'.
3
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is a type of attack that forces an authenticated user to perform unwanted actions on a web application in which they are authenticated.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by an attacker tricking an authenticated user of the affected plugin into performing malicious actions on their behalf.
5
How can I fix this vulnerability?
To fix this vulnerability, update the Schema Pro plugin to version 2.7.8 or later.