CVE-2023-6389

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 29, 2024
Updated: Feb 3, 2024
CWE ID 601

Summary

CVE-2023-6389 is a vulnerability affecting the WordPress Toolbar plugin before version 2.2.7. Attackers can exploit this issue by manipulating the "wptbto" parameter to redirect users to malicious sites, even without authentication. This security flaw poses a significant risk as it allows attackers to potentially harm unsuspecting users through redirects to deceptive or malicious websites. The plugin's developers have released an updated version (2.2.7) to address this vulnerability, and users are strongly encouraged to upgrade as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share