CVE-2023-52136: WordPress Custom Twitter Feeds (Tweets Widget) Plugin <= 2.1.2 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget or X Feed Widget: from n/a through 2.1.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52136?
CVE-2023-52136 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions being performed on behalf of a user.
How do I fix CVE-2023-52136?
To fix CVE-2023-52136, update the Smash Balloon Custom Twitter Feeds plugin to version 2.1.3 or later.
What versions are affected by CVE-2023-52136?
CVE-2023-52136 affects Smash Balloon Custom Twitter Feeds versions up to and including 2.1.2.
What types of attacks are possible with CVE-2023-52136?
CVE-2023-52136 allows attackers to potentially perform unauthorized actions on behalf of users due to the CSRF vulnerability.
Is authentication bypass possible with CVE-2023-52136?
CVE-2023-52136 does not directly allow authentication bypass, but it can exploit authenticated user sessions to execute unintended actions.