CVE-2023-4150

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 30, 2023
Updated: Nov 7, 2023
CWE ID 434

Summary

CVE-2023-4150 is a vulnerability affecting the User Activity Tracking and Log WordPress plugin before version 4.0.9. This issue allows attackers to execute unauthorized plugin license updates and deactivations on logged-in admin accounts through Cross-Site Request Forgery (CSRF) attacks. The plugin fails to implement sufficient CSRF protection, making it vulnerable to these attacks. Attackers could exploit this to disrupt plugin functionality or gain unauthorized access to affected sites. It is recommended that users of the plugin upgrade to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share