CVE-2023-49164: WordPress Ocean Extra Plugin <= 2.2.2 is vulnerable to Cross Site Request Forgery (CSRF)
Published Dec 19, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.
Affected Software
1 affected component
Oceanwp Ocean Extra WordPress<2.2.3
Remediation
Information
Update to 2.2.3 or a higher version.
Event History
Dec 19, 2023
CVE Published
via MITRE·09:41 PM
Data Sourced
via MITRE·09:41 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49164?
CVE-2023-49164 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-49164?
To remediate CVE-2023-49164, update the Ocean Extra plugin to version 2.2.3 or later.
3
Which versions of Ocean Extra are affected by CVE-2023-49164?
CVE-2023-49164 affects Ocean Extra versions from n/a up to and including 2.2.2.
4
What type of vulnerability is CVE-2023-49164?
CVE-2023-49164 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2023-49164 lead to arbitrary actions on my WordPress site?
Yes, CVE-2023-49164 can allow attackers to perform arbitrary actions, including plugin activation, on the affected WordPress sites.