CVE-2023-52128: WordPress White Label Plugin <= 2.9.0 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jan 5, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WhiteWP White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard.This issue affects White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard: from n/a through 2.9.0.
Affected Software
1 affected component
Linksoftwarellc White Label Wordpress<=2.9.0
Remediation
Information
Update to 2.9.1 or a higher version.
Event History
Jan 5, 2024
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52128?
CVE-2023-52128 is classified as a medium-severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-52128?
To fix CVE-2023-52128, update the White Label – WordPress Custom Admin plugin to version 2.9.1 or later.
3
What versions are affected by CVE-2023-52128?
CVE-2023-52128 affects versions of the White Label – WordPress Custom Admin plugin up to and including 2.9.0.
4
What is the impact of CVE-2023-52128?
The impact of CVE-2023-52128 allows attackers to perform unauthorized actions on behalf of an authenticated user.
5
Is there a known exploit for CVE-2023-52128?
As of now, there are no publicly known exploits for CVE-2023-52128.