PT-2024-14945 · WordPress · Wordpress Ping Optimizer

Jan W Oleju

·

Published

2024-04-10

·

Updated

2025-05-19

·

CVE-2023-6385

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WordPress Ping Optimizer plugin versions through 2.35.1.3.0
Description The issue concerns the lack of CSRF checks in certain areas, potentially allowing attackers to trick logged-in users into performing unwanted actions, such as clearing logs, via CSRF attacks.
Recommendations For WordPress Ping Optimizer plugin versions through 2.35.1.3.0, update to a version that includes CSRF checks to prevent such attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-6385

Affected Products

Wordpress Ping Optimizer