CVE · Medium

CVE-2023-22673 — Website Monetization by MageNet [website-monetization-by-magenet] < 1.0.29.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-22673 Website Monetization by MageNet [website-monetization-by-magenet] < 1.0.29.2 Cross-Site Request Forgery (CSRF) Medium 5.4 < 1.0.29.2 1.0.29.2 2023-03-16

CVE-2023-22673

The Website Monetization by MageNet plugin through version 1.0.29.1 contains a CSRF vulnerability because the admin_magenet_settings function fails to properly verify nonce tokens. An attacker could craft a malicious request that, if clicked by an authenticated administrator, would allow the attacker to change the plugin's configuration settings without authorization. This flaw affects all versions up to and including 1.0.29.1 and is corrected in version 1.0.29.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.