First published: Mon Sep 11 2023(Updated: )
The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-company Herd Effects | <5.2.4 | |
<5.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-4318.
The title of this vulnerability is 'The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack'.
The severity of CVE-2023-4318 is medium with a severity value of 4.3.
CVE-2023-4318 impacts the Herd Effects WordPress plugin by allowing attackers to make logged in admins delete arbitrary effects via a CSRF attack.
To fix CVE-2023-4318, update the Herd Effects WordPress plugin to version 5.2.4 or higher.