Sploitus

CVE-2023-6390

1 known exploit for CVE-2023-6390

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Affected products
Wordpress Users
Jonathonkemp Wordpress Users
≤ 1.4.0
CVSS 3.1
8.8 HIGH
EPSS
0.3% (26th percentile)
Weakness
CWE-352
NVD status
Modified
Published
2024-01-29
CVE-2023-6390 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2023-6390

Proof-of-concept code and exploit modules indexed by Sploitus