CVE · Medium

CVE-2023-3254 — Widgets for Google Reviews [wp-reviews-plugin-for-google] < 10.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3254 Widgets for Google Reviews [wp-reviews-plugin-for-google] < 10.9.1 Cross-Site Request Forgery (CSRF) Medium 4.3 < 10.9.1 10.9.1 2023-10-16

CVE-2023-3254

The Widgets for Google Reviews plugin for WordPress through version 10.9 contains a Cross-Site Request Forgery vulnerability caused by insufficient nonce verification in the setup_no_reg_header.php file. Unauthenticated attackers can exploit this flaw to reset plugin configuration and delete reviews if they can social engineer a site administrator into clicking a malicious link. The vulnerability was fixed in version 10.9.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.