4.3
CVE-2023-2271
- EPSS 0.06%
- Veröffentlicht 16.08.2023 12:15:12
- Zuletzt bearbeitet 21.11.2024 07:58:17
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Tiempo.com <= 0.1.2 - Cross-Site Request Forgery to Shortcode Deletion
The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack
Mögliche Gegenmaßnahme
Tiempo.com: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Tiempo.com
Version
*-0.1.2
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.175 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|