CVE-2023-4731 affects the LadiApp WordPress plugin, versions up to and including 4.4, due to a Cross-Site Request Forgery (CSRF) vulnerability. This medium-severity flaw (CVSS 4.3) allows unauthenticated attackers to modify plugin settings, including the 'ladipage_key', by tricking an administrator into clicking a malicious link. Successful exploitation could lead to the creation of new posts and injection of malicious web scripts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4CPE matchmatch criteria | cpe:2.3:a:ladipage:ladipage:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.