CVE-2023-48762: WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF)
Published Dec 18, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
Affected Software
1 affected component
Crocoblock Jetelements For Elementor Wordpress<2.6.13.1
Remediation
Information
Update to 2.6.13.1 or a higher version.
Event History
Dec 18, 2023
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-48762?
The severity of CVE-2023-48762 is considered high due to its potential to exploit Cross-Site Request Forgery vulnerabilities.
2
How do I fix CVE-2023-48762?
To fix CVE-2023-48762, update the JetElements for Elementor plugin to version 2.6.13.1 or later.
3
What versions are affected by CVE-2023-48762?
CVE-2023-48762 affects JetElements for Elementor versions from n/a up to and including 2.6.13.
4
Can CVE-2023-48762 lead to unauthorized actions?
Yes, CVE-2023-48762 can allow attackers to perform unauthorized actions on behalf of authenticated users.
5
What is a Cross-Site Request Forgery (CSRF) vulnerability?
A Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to trick a user into submitting requests that they did not intend to make.