PT-2023-16967 · WordPress · Wp Vr

·

CVE-2023-1414

·

Published

2023-04-24

·

Updated

2025-02-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP VR WordPress plugin versions prior to 8.3.0
Description The issue concerns a lack of authorization and CSRF checks in various AJAX actions within the WP VR WordPress plugin. This could allow any authenticated user, such as a subscriber, to update arbitrary tours.
Recommendations For versions prior to 8.3.0, update to version 8.3.0 or later to resolve the issue.

Exploit

Fix

CSRF

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-1414

Affected Products

Wp Vr