CVE-2023-5975
Last modified
CVE-2023-5975 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. This is due to missing or incorrect nonce validation on multiple functions. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to update the plugin settings via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Imagemapper Project | Imagemapper | <= 1.2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5975?
How severe is CVE-2023-5975?
How do I fix CVE-2023-5975?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-5969Mattermost fails to properly sanitize the request to /api/v4…5.3
- CVE-2023-5970Improper authentication in the SMA100 SSL-VPN virtual office…8.8
- CVE-2023-5971The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3…4.8
- CVE-2023-5972A null pointer dereference flaw was found in the nft_inner.c…7.8
- CVE-2023-5973Brocade Web Interface in Brocade Fabric OS v9.x and before …4.3
- CVE-2023-5974The WPB Show Core WordPress plugin through 2.2 is vulnerable…9.8
- CVE-2023-5976Improper Access Control in GitHub repository microweber/micr…4.3
- CVE-2023-5977Rejected reason: Accidental Request.
- CVE-2023-5978In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, unde…7.5
- CVE-2023-5979The eCommerce Product Catalog Plugin for WordPress plugin be…6.5
- CVE-2023-5980The BSK Forms Blacklist WordPress plugin before 3.7 does not…4.8
- CVE-2023-5981A vulnerability was found that the response times to malform…5.9
Are you affected by CVE-2023-5975?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
