First published: Thu Oct 12 2023(Updated: )
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
I13websolution Thumbnail Slider With Lightbox | <=1.0 | |
<=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5531 refers to a vulnerability in the Thumbnail Slider With Lightbox plugin for WordPress that allows cross-site request forgery attacks.
CVE-2023-5531 has a severity rating of medium, with a CVSS score of 4.3.
CVE-2023-5531 affects versions of the Thumbnail Slider With Lightbox plugin up to and including 1.0, allowing unauthenticated attackers to delete image lightboxes through missing or incorrect nonce validation.
To fix CVE-2023-5531, updating to a version of the Thumbnail Slider With Lightbox plugin that includes proper nonce validation is necessary.
More information about CVE-2023-5531 can be found at the following references: [Link 1](https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=1263536%40wp-responsive-slider-with-lightbox&new=1263536%40wp-responsive-slider-with-lightbox&sfp_email=&sfph_mail=), [Link 2](https://wordpress.org/plugins/wp-responsive-slider-with-lightbox/), [Link 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/055b7ed5-268a-485e-ac7d-8082dc9fb2ad?source=cve)