PT-2023-22813 · WordPress · Form Block
Daniel Ruf
·
Published
2023-04-20
·
Updated
2023-05-01
·
CVE-2023-30616
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Form block versions prior to 1.0.2
Description
The Form block WordPress plugin is subject to a Cross-Site Request Forgery (CSRF) due to a missing nonce check. This allows requests to be sent to forms from any website without the user's knowledge. The issue affects all form blocks, enabling potential CSRF attacks.
Recommendations
For versions prior to 1.0.2, upgrade to version 1.0.2 to resolve the issue.
At the moment, there is no information about other workarounds for this vulnerability.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Form Block