First published: Fri Dec 29 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WPExpertsio New User Approve.This issue affects New User Approve: from n/a through 2.5.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpexperts New User Approve | <=2.5.1 |
Update to 2.5.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50902 has a medium severity rating due to its potential for Cross-Site Request Forgery (CSRF) attacks.
To fix CVE-2023-50902, update the New User Approve plugin to version 2.5.2 or higher.
CVE-2023-50902 affects New User Approve versions from n/a through 2.5.1.
Yes, CVE-2023-50902 can lead to unauthorized actions being performed on behalf of authenticated users.
A recommended workaround for CVE-2023-50902 is to temporarily disable the New User Approve plugin until the update is applied.