6.5
CVSSv3

CVE-2023-5884

Published: 04/12/2023 Updated: 08/12/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Word Balloon WordPress plugin prior to 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated malicious user to trick a logged in user to delete arbitrary avatars by clicking a link.

Vulnerable Product Search on Vulmon Subscribe to Product

back2nature word balloon