CVE-2023-46189: WordPress Google Calendar Events Plugin <= 3.2.5 is vulnerable to Cross Site Request Forgery (CSRF)
Published Oct 24, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Simple Calendar – Google Calendar Plugin <= 3.2.5 versions.
Affected Software
1 affected component
Xtendify Simple Calendar Wordpress<3.2.6
Event History
Oct 24, 2023
CVE Published
via MITRE·10:20 AM
Data Sourced
via MITRE·10:20 AM
DescriptionSeverityWeakness
Oct 25, 2023
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46189?
The severity of CVE-2023-46189 is high.
2
What is the vulnerability description of CVE-2023-46189?
CVE-2023-46189 is a Cross-Site Request Forgery (CSRF) vulnerability in Simple Calendar – Google Calendar Plugin <= 3.2.5 versions.
3
What software versions are affected by CVE-2023-46189?
Versions up to and excluding Simple Calendar – Google Calendar Plugin 3.2.6 are affected by CVE-2023-46189.
4
How can I fix CVE-2023-46189?
To fix CVE-2023-46189, update Simple Calendar – Google Calendar Plugin to version 3.2.6 or higher.
5
What is the Common Weakness Enumeration (CWE) ID of CVE-2023-46189?
The Common Weakness Enumeration (CWE) ID of CVE-2023-46189 is 352.