ZeroHour

CVE-2023-4318

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p17
Published
()
Modified
Description

The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

Vendors
wow-company
Products
herd effects
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.