The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.
Metrics
Affected Vendors & Products
References
History
Mon, 21 Oct 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-17T14:31:48.144Z
Updated: 2024-10-21T11:56:23.125Z
Reserved: 2023-09-15T21:03:54.448Z
Link: CVE-2023-5006
Vulnrichment
Updated: 2024-08-02T07:44:53.694Z
NVD
Status : Modified
Published: 2024-01-17T15:15:10.803
Modified: 2024-11-21T08:40:52.410
Link: CVE-2023-5006
Redhat
No data.