The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation on the 'enable_safe_mode' function. This makes it possible for unauthenticated attackers to enable safe mode, which disables all other plugins, via a forged request if they can successfully trick an administrator into performing an action such as clicking on a link. A warning message about safe mode is displayed to the admin, which can be easily disabled.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2023-05-20T02:03:24.840Z
Updated: 2024-08-02T06:33:04.534Z
Reserved: 2023-05-15T16:57:58.649Z
Link: CVE-2023-2717
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-20T03:15:09.233
Modified: 2023-11-07T04:13:12.950
Link: CVE-2023-2717
Redhat
No data.