CVE-2023-5531: Thumbnail Slider With Lightbox <= 1.0 - Cross-Site Request Forgery
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-5531?
CVE-2023-5531 refers to a vulnerability in the Thumbnail Slider With Lightbox plugin for WordPress that allows cross-site request forgery attacks.
What is the severity of CVE-2023-5531?
CVE-2023-5531 has a severity rating of medium, with a CVSS score of 4.3.
How does CVE-2023-5531 affect the Thumbnail Slider With Lightbox plugin?
CVE-2023-5531 affects versions of the Thumbnail Slider With Lightbox plugin up to and including 1.0, allowing unauthenticated attackers to delete image lightboxes through missing or incorrect nonce validation.
What is the fix for CVE-2023-5531?
To fix CVE-2023-5531, updating to a version of the Thumbnail Slider With Lightbox plugin that includes proper nonce validation is necessary.
Where can I find more information about CVE-2023-5531?
More information about CVE-2023-5531 can be found at the following references: [Link 1](https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=1263536%40wp-responsive-slider-with-lightbox&new=1263536%40wp-responsive-slider-with-lightbox&sfp_email=&sfph_mail=), [Link 2](https://wordpress.org/plugins/wp-responsive-slider-with-lightbox/), [Link 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/055b7ed5-268a-485e-ac7d-8082dc9fb2ad?source=cve)