CVE · Medium

CVE-2023-0831 — Under Construction [under-construction-page] < 3.97

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0832, CVE-2023-0831 Under Construction [under-construction-page] < 3.97 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.97 3.97 2023-02-10

CVE-2023-0832, CVE-2023-0831

The Under Construction plugin for WordPress through version 3.96 contains a Cross-Site Request Forgery vulnerability in the install_weglot function, which lacks proper nonce verification. An unauthenticated attacker could exploit this flaw to install the Weglot Translate plugin without authorization if they convince a site administrator to click a malicious link. The vulnerability affects the admin_action_install_weglot action handler and was fixed in version 3.97.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.