CVE · Medium

CVE-2023-25480 — Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.24.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-25480 Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.24.2 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.24.2 1.24.2 2023-08-22

CVE-2023-25480

The Post and Page Builder by BoldGrid plugin before version 1.24.2 contains a cross-site request forgery vulnerability affecting the submitDefaultEditor function, which fails to properly verify nonce tokens. An attacker could exploit this flaw by deceiving an administrator into clicking a malicious link, allowing the attacker to modify the plugin's editor preferences without proper authorization. This vulnerability impacts unauthenticated attackers and only requires social engineering to execute successfully.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.