CVE · Medium

CVE-2023-0832 — Under Construction [under-construction-page] < 3.97

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0832, CVE-2023-0831 Under Construction [under-construction-page] < 3.97 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.97 3.97 2023-02-10

CVE-2023-0832, CVE-2023-0831

The Under Construction plugin for WordPress through version 3.96 contains a CSRF vulnerability affecting the install_weglot function, which is triggered by the admin_action_install_weglot action and lacks proper nonce verification. An unauthenticated attacker could exploit this flaw by crafting a malicious request that, if clicked by an administrator, would install the Weglot Translate plugin without authorization. The vulnerability requires social engineering to trick an admin user into following a crafted link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.