CVE-2023-4277
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Aug 10, 2023
Updated: Nov 7, 2023
CWE ID 306
CWE ID 288
Summary
CVE-2023-4277 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Realia plugin for WordPress. Versions up to and including 1.4.0 are impacted by this issue. Malicious actors can exploit this weakness by forging requests to trick site administrators into performing actions, such as clicking on malicious links. As a result, unauthenticated attackers are able to change user email addresses. This vulnerability arises due to the absence of nonce validation on the 'process_change_profile_form' function within the plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Red Lion Controls Inc.