CVE-2023-4731

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 12, 2024
CWE ID 798

Summary

CVE-2023-4731 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the LadiApp plugin for WordPress. This issue is caused by a missing nonce check on the init_endpoint() function, which can be exploited by unauthenticated attackers. By tricking a site administrator into performing an action, such as clicking on a malicious link, the attacker can modify various settings including the 'ladipage_key'. This allows the attacker to create new posts and inject malicious web scripts, potentially leading to a compromised website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share