CVE-2023-4318: Herd Effects < 5.2.4 - Effect Deletion via CSRF
The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-4318.
What is the title of this vulnerability?
The title of this vulnerability is 'The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack'.
What is the severity of CVE-2023-4318?
The severity of CVE-2023-4318 is medium with a severity value of 4.3.
How does CVE-2023-4318 impact the Herd Effects WordPress plugin?
CVE-2023-4318 impacts the Herd Effects WordPress plugin by allowing attackers to make logged in admins delete arbitrary effects via a CSRF attack.
How do I fix CVE-2023-4318?
To fix CVE-2023-4318, update the Herd Effects WordPress plugin to version 5.2.4 or higher.