First published: Wed Aug 30 2023(Updated: )
The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset the plugin's settings and update its API key via CSRF attacks.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ht Editor | <0.9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-4209.
The severity of CVE-2023-4209 is medium.
Version 0.9.8 of the POEditor WordPress plugin is affected by CVE-2023-4209.
Attackers can make logged in admins perform unwanted actions, such as resetting the plugin's settings and updating its API key via CSRF attacks.
Yes, upgrading to version 0.9.8 of the POEditor WordPress plugin or higher fixes CVE-2023-4209.