CVE-2023-36690: WordPress WPLMS Theme < 4.900 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jul 11, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.
Affected Software
2 affected components
WPLMS Learning Management System for WordPress<=4.900
VibeThemes Wordpress Learning Management System Wordpress<=4.900
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VibeThemes WPLMS themeto a version that resolves this vulnerability.Fixed in 4.900
Event History
Jul 11, 2023
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-36690?
CVE-2023-36690 is classified as a high-severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-36690?
To fix CVE-2023-36690, update the VibeThemes WPLMS theme to version 4.901 or later.
3
What are the potential impacts of CVE-2023-36690?
The vulnerability can allow attackers to perform unauthorized actions on behalf of authenticated users.
4
Who is affected by CVE-2023-36690?
Users running VibeThemes WPLMS theme versions up to 4.900 are affected by CVE-2023-36690.
5
What action should be taken if CVE-2023-36690 is exploited?
If exploited, immediate steps should be taken to update the theme and review user access logs for suspicious activities.