CVE-2023-23897
WordPress Simple Mobile URL Redirect Plugin <= 1.7.2 is vulnerable to Cross Site Request Forgery (CSRF)
Record summary
CVE-2023-23897 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.
Description
Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 30, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Simple Mobile URL RedirectBrowse Ozette Plugins / Simple Mobile URL RedirectDefault status: unaffected | CVE List | Through 1.7.2 | affected |
simple_mobile_url_redirectBrowse ozette / simple_mobile_url_redirect | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMOzette Plugins - Cross-Site Request ForgeryCVSS 4.3
An attacker can update, create, and remove the site's mobile redirects via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Impact
Attackers can perform unauthorized actions on behalf of authenticated users, potentially leading to data manipulation or unauthorized redirects.
Remediation
Update to version 1.7.3 or later with CSRF protections implemented.
Source: ProjectDiscovery