{ "id": "CVE-2023-4209", "sourceIdentifier": "contact@wpscan.com", "published": "2023-08-30T15:15:10.047", "lastModified": "2023-11-07T04:22:20.387", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset the plugin's settings and update its API key via CSRF attacks." }, { "lang": "es", "value": "El plugin de WordPress POEditor anterior a la versi\u00f3n 0.9.8 no tiene comprobaciones CSRF en varios lugares, lo que podr\u00eda permitir a los atacantes hacer que los administradores registrados realicen acciones no deseadas, como restablecer la configuraci\u00f3n del plugin y actualizar su clave de API a trav\u00e9s de ataques CSRF." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseScore": 4.3, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 1.4 } ] }, "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:poeditor:poeditor:*:*:*:*:*:wordpress:*:*", "versionEndExcluding": "0.9.8", "matchCriteriaId": "F10661B0-9B0A-4431-A499-C8275A6D6506" } ] } ] } ], "references": [ { "url": "https://wpscan.com/vulnerability/b2c6fa7d-1b0f-444b-8ca5-8c1c06cea1d9", "source": "contact@wpscan.com", "tags": [ "Exploit", "Third Party Advisory" ] } ] }