CVE-2023-40009: WordPress WP Pipes Plugin <= 1.4.0 is vulnerable to Cross Site Request Forgery (CSRF)
Published Oct 3, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions.
Affected Software
1 affected component
Thimpress WP Pipes<=1.4.0
Remediation
Information
Update to 1.4.1 or a higher version.
Event History
Oct 3, 2023
CVE Published
via MITRE·12:45 PM
Data Sourced
via MITRE·12:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-40009?
CVE-2023-40009 is a Cross-Site Request Forgery (CSRF) vulnerability found in the ThimPress WP Pipes plugin versions up to 1.4.0.
2
What is the severity of CVE-2023-40009?
CVE-2023-40009 has a severity rating of 6.5 (Medium).
3
How does CVE-2023-40009 affect the ThimPress WP Pipes plugin?
CVE-2023-40009 allows attackers to perform Cross-Site Request Forgery (CSRF) attacks on websites that have the ThimPress WP Pipes plugin installed with versions up to 1.4.0.
4
Is there a fix for CVE-2023-40009?
Yes, the fix for CVE-2023-40009 is available in the 1.4.1 version of the ThimPress WP Pipes plugin.
5
Where can I find more information about CVE-2023-40009?
More information about CVE-2023-40009 can be found at https://patchstack.com/database/vulnerability/wp-pipes/wordpress-wp-pipes-plugin-1-4-0-multiple-cross-site-request-forgery-csrf-vulnerability.