PT-2023-22813 · WordPress · Form Block

Daniel Ruf

·

Published

2023-04-20

·

Updated

2023-05-01

·

CVE-2023-30616

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Form block versions prior to 1.0.2
Description The Form block WordPress plugin is subject to a Cross-Site Request Forgery (CSRF) due to a missing nonce check. This allows requests to be sent to forms from any website without the user's knowledge. The issue affects all form blocks, enabling potential CSRF attacks.
Recommendations For versions prior to 1.0.2, upgrade to version 1.0.2 to resolve the issue. At the moment, there is no information about other workarounds for this vulnerability.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-30616
GHSA-J4C2-7P87-Q824

Affected Products

Form Block