CVE-2023-2497

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 22, 2023
Updated: Dec 4, 2023
CWE ID 125

Summary

CVE-2023-2497 is a vulnerability affecting the UserPro plugin for WordPress. This issue allows unauthenticated attackers to execute Cross-Site Request Forgery (CSRF) attacks on versions up to 5.1.0. The root cause is insufficient nonce validation on the 'import_settings' function. As a result, attackers can exploit PHP Object Injection via unserialize() of user-supplied data. To successfully carry out an attack, an attacker needs to trick a site administrator into performing a specific action, such as clicking on a malicious link.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share