CVE-2023-4209

The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset the plugin's settings and update its API key via CSRF attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:poeditor:poeditor:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:34

Type Values Removed Values Added
Summary
  • (es) El plugin de WordPress POEditor anterior a la versión 0.9.8 no tiene comprobaciones CSRF en varios lugares, lo que podría permitir a los atacantes hacer que los administradores registrados realicen acciones no deseadas, como restablecer la configuración del plugin y actualizar su clave de API a través de ataques CSRF.
References () https://wpscan.com/vulnerability/b2c6fa7d-1b0f-444b-8ca5-8c1c06cea1d9 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/b2c6fa7d-1b0f-444b-8ca5-8c1c06cea1d9 - Exploit, Third Party Advisory

Information

Published : 2023-08-30 15:15

Updated : 2025-04-23 17:16


NVD link : CVE-2023-4209

Mitre link : CVE-2023-4209

CVE.ORG link : CVE-2023-4209


JSON object : View

Products Affected

poeditor

  • poeditor
CWE

No CWE.