8.8
CVSSv3

CVE-2023-6390

Published: 29/01/2024 Updated: 03/02/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The WordPress Users WordPress plugin up to and including 1.4 does not have CSRF check in place when updating its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack.

Vulnerable Product Search on Vulmon Subscribe to Product

jonathonkemp wordpress users