Vulnerability Description
The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jeremiahorem | Custom User Css | <= 0.2 |
Related Weaknesses (CWE)
References
- https://magos-securitas.com/txt/CVE-2023-6391.txtExploit
- https://wpscan.com/vulnerability/4098b18d-6ff3-462c-af05-48adb6599cf3/ExploitThird Party Advisory
- https://magos-securitas.com/txt/CVE-2023-6391.txtExploit
- https://wpscan.com/vulnerability/4098b18d-6ff3-462c-af05-48adb6599cf3/ExploitThird Party Advisory
FAQ
What is CVE-2023-6391?
CVE-2023-6391 is a vulnerability with a CVSS score of 8.8 (HIGH). The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
How severe is CVE-2023-6391?
CVE-2023-6391 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6391?
Check the references section above for vendor advisories and patch information. Affected products include: Jeremiahorem Custom User Css.