CVE-2023-4277

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 10, 2023
Updated: Nov 7, 2023
CWE ID 306
CWE ID 288

Summary

CVE-2023-4277 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Realia plugin for WordPress. Versions up to and including 1.4.0 are impacted by this issue. Malicious actors can exploit this weakness by forging requests to trick site administrators into performing actions, such as clicking on malicious links. As a result, unauthenticated attackers are able to change user email addresses. This vulnerability arises due to the absence of nonce validation on the 'process_change_profile_form' function within the plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share