CVE-2023-50902: WordPress New User Approve Plugin <= 2.5.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published Dec 29, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WPExpertsio New User Approve.This issue affects New User Approve: from n/a through 2.5.1.
Affected Software
1 affected component
Wpexperts New User Approve Wordpress<=2.5.1
Remediation
Information
Update to 2.5.2 or a higher version.
Event History
Dec 29, 2023
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50902?
CVE-2023-50902 has a medium severity rating due to its potential for Cross-Site Request Forgery (CSRF) attacks.
2
How do I fix CVE-2023-50902?
To fix CVE-2023-50902, update the New User Approve plugin to version 2.5.2 or higher.
3
What versions of New User Approve are affected by CVE-2023-50902?
CVE-2023-50902 affects New User Approve versions from n/a through 2.5.1.
4
Can CVE-2023-50902 lead to unauthorized actions?
Yes, CVE-2023-50902 can lead to unauthorized actions being performed on behalf of authenticated users.
5
Is there a workaround for CVE-2023-50902 until it is patched?
A recommended workaround for CVE-2023-50902 is to temporarily disable the New User Approve plugin until the update is applied.