CVE-2023-36517

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to trick a user into performing actions on their WordPress site without their consent, potentially leading to unauthorized changes or data exposure. It requires the user to be logged into their account and to click on a malicious link while visiting a compromised website.

Technical Description

Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References