CVE Database /
CVE-2023-25480
CVE · Medium
CVE-2023-25480 — Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.24.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-25480
|
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.24.2 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 1.24.2
|
1.24.2 |
2023-08-22 |
—
|
CVE-2023-25480
The Post and Page Builder by BoldGrid plugin before version 1.24.2 contains a cross-site request forgery vulnerability affecting the submitDefaultEditor function, which fails to properly verify nonce tokens. An attacker could exploit this flaw by deceiving an administrator into clicking a malicious link, allowing the attacker to modify the plugin's editor preferences without proper authorization. This vulnerability impacts unauthenticated attackers and only requires social engineering to execute successfully.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings