CVE-2023-38396: WordPress Google Map Shortcode Plugin <= 3.1.2 is vulnerable to Cross Site Request Forgery (CSRF)
Published Oct 3, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions.
Affected Software
1 affected component
Web-argument Google-map-shortcode Wordpress<=3.1.2
Event History
Oct 3, 2023
CVE Published
via MITRE·10:22 AM
Data Sourced
via MITRE·10:22 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-38396.
2
What is the severity of CVE-2023-38396?
The severity of CVE-2023-38396 is high with a CVSS score of 8.8.
3
What is the affected software of CVE-2023-38396?
The affected software of CVE-2023-38396 is the Google-map-shortcode plugin version <= 3.1.2 for WordPress.
4
What is the vulnerability description of CVE-2023-38396?
CVE-2023-38396 is a Cross-Site Request Forgery (CSRF) vulnerability in the Google-map-shortcode plugin <= 3.1.2 versions.
5
How can I fix CVE-2023-38396?
To fix CVE-2023-38396, it is recommended to update the Google-map-shortcode plugin to a version that is higher than 3.1.2.