4.3
CVE-2023-4318
- EPSS 0.07%
- Veröffentlicht 11.09.2023 20:15:12
- Zuletzt bearbeitet 23.04.2025 17:16:43
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Herd Effects <= 5.2.3 - Cross-Site Request Forgery to Effect Deletion
The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack
Mögliche Gegenmaßnahme
Social Proof Popups & Real-Time Notifications – Herd Effects: Update to version 5.2.4, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Social Proof Popups & Real-Time Notifications – Herd Effects
Version
* - 5.2.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wow-company ≫ Herd Effects SwPlatformwordpress Version < 5.2.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.207 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|