CVE-2023-1623
24.04.2023, 19:15
The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.Enginsight
Vendor | Product | Version |
---|---|---|
webdevstudios | custom_post_type_ui | 𝑥 < 1.13.5 |
𝑥
= Vulnerable software versions