CVE-2023-7297: TwitterPosts <= 1.0.2 - Settings Update via CSRF
Published May 15, 2025
·Updated
The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
2 affected components
WordPress TwitterPosts<=1.0.2
Reneade Twitterposts Wordpress<=1.0.2
Event History
May 15, 2025
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-7297?
CVE-2023-7297 is classified as a high severity vulnerability due to the potential for CSRF attacks on admin settings.
2
How do I fix CVE-2023-7297?
To fix CVE-2023-7297, update the TwitterPosts plugin to a version higher than 1.0.2 where the CSRF protection has been implemented.
3
Who is affected by CVE-2023-7297?
CVE-2023-7297 affects users of the TwitterPosts WordPress plugin version 1.0.2 and below.
4
What type of vulnerability is CVE-2023-7297?
CVE-2023-7297 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2023-7297 be exploited remotely?
Yes, CVE-2023-7297 can potentially be exploited remotely by an attacker who tricks an authenticated admin into executing harmful requests.