CVE-2023-51489: WordPress Crowdsignal Polls & Ratings plugin <= 3.0.11 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51489?
CVE-2023-51489 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that can lead to unauthorized actions being taken on behalf of users.
How do I fix CVE-2023-51489?
To fix CVE-2023-51489, upgrade the Crowdsignal Dashboard to version 3.1.0 or later.
Which versions of the Crowdsignal Dashboard are affected by CVE-2023-51489?
Versions of the Crowdsignal Dashboard from the initial release up to and including 3.0.11 are affected by CVE-2023-51489.
What can attackers achieve with CVE-2023-51489?
Attackers exploiting CVE-2023-51489 can perform unauthorized actions by tricking users into executing commands without their consent.
Is it necessary to take action for CVE-2023-51489?
Yes, it is necessary to take action to prevent potential exploitation of CVE-2023-51489 and protect user data.