6.5
CVE-2023-1331
- EPSS 0.12%
- Veröffentlicht 17.04.2023 13:15:38
- Zuletzt bearbeitet 06.02.2025 17:15:15
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Redirection <= 1.1.4 - Cross-Site Request Forgery to Plugin Reset
The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
Mögliche Gegenmaßnahme
Redirection: Update to version 1.1.5, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Redirection
Version
*-1.1.4
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Inisev ≫ Redirection SwPlatformwordpress Version < 1.1.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.313 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|