CVE-2023-39166: WordPress tagDiv Composer Plugin < 4.4 is vulnerable to Cross Site Request Forgery (CSRF)
Published Nov 13, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from n/a before 4.4.
Affected Software
1 affected component
tagDiv tagDiv Composer WordPress<4.4
Remediation
Information
Update to 4.4 or a higher version.
Event History
Nov 13, 2023
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2023-39166.
2
What is the severity of CVE-2023-39166?
The severity of CVE-2023-39166 is high.
3
Which software is affected by CVE-2023-39166?
The tagDiv Composer plugin version before 4.4 in WordPress is affected by CVE-2023-39166.
4
What is the vulnerability type in CVE-2023-39166?
CVE-2023-39166 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
How can I fix CVE-2023-39166?
To fix CVE-2023-39166, update the tagDiv Composer plugin to version 4.4 or newer.