CVE-2023-4150
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-4150 is a vulnerability affecting the User Activity Tracking and Log WordPress plugin before version 4.0.9. This issue allows attackers to execute unauthorized plugin license updates and deactivations on logged-in admin accounts through Cross-Site Request Forgery (CSRF) attacks. The plugin fails to implement sufficient CSRF protection, making it vulnerable to these attacks. Attackers could exploit this to disrupt plugin functionality or gain unauthorized access to affected sites. It is recommended that users of the plugin upgrade to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.