PT-2023-22813 · WordPress · Form Block

·

CVE-2023-30616

·

Publicado

2023-04-20

·

Atualizado

2023-05-01

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Form block versions prior to 1.0.2
Description The Form block WordPress plugin is subject to a Cross-Site Request Forgery (CSRF) due to a missing nonce check. This allows requests to be sent to forms from any website without the user's knowledge. The issue affects all form blocks, enabling potential CSRF attacks.
Recommendations For versions prior to 1.0.2, upgrade to version 1.0.2 to resolve the issue. At the moment, there is no information about other workarounds for this vulnerability.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30616
GHSA-J4C2-7P87-Q824

Produtos afetados

Form Block