CVE-2023-46212
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-46212 is a Cross-Site Request Forgery (CSRF) vulnerability affecting TienCOP WP EXtra from version n/a through 6.2. This issue results in unauthorized access to functionality that is not properly constrained by Access Control Lists (ACLs). An attacker can exploit this CSRF vulnerability by tricking a user into performing an unintended action on a website, potentially leading to sensitive data exposure or unauthorized system modifications. This weakness can pose a significant risk to websites using the vulnerable version of WP EXtra and should be addressed promptly by updating to a secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.