The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
History

Tue, 27 May 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Evanliewer
Evanliewer illi Link Party\!
Weaknesses CWE-352
CPEs cpe:2.3:a:evanliewer:illi_link_party\!:*:*:*:*:*:wordpress:*:*
Vendors & Products Evanliewer
Evanliewer illi Link Party\!

Fri, 16 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
Title illi Link Party! <= 1.0 - Settings Update via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:09:26.333Z

Updated: 2025-05-16T16:51:49.332Z

Reserved: 2024-01-11T02:46:32.195Z

Link: CVE-2023-7229

cve-icon Vulnrichment

Updated: 2025-05-16T16:51:41.971Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:30.677

Modified: 2025-05-27T20:02:45.827

Link: CVE-2023-7229

cve-icon Redhat

No data.