PT-2023-25677 · WordPress · Schema Pro

Rafie Muhammad

·

Published

2023-11-30

·

Updated

2025-06-27

·

CVE-2023-36682

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Schema Pro versions through 2.7.7
Description A Cross-Site Request Forgery (CSRF) issue allows unauthorized actions to be performed on behalf of a user. This issue affects the Schema Pro plugin, enabling Cross Site Request Forgery.
Recommendations For versions through 2.7.7, update to a version later than 2.7.7 to resolve the issue. At the moment, there is no information about additional mitigation measures for this issue.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-36682

Affected Products

Schema Pro