CVE-2023-3320 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WP Sticky Social plugin for WordPress, versions up to and including 1.0.1. This flaw, stemming from missing nonce validation, allows unauthenticated attackers to modify plugin settings and inject malicious web scripts if they can trick a site administrator into clicking a crafted link. Rated with a CVSS score of 8.8 (High), this vulnerability has a high impact on confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. While not currently listed on the KEV catalog or experiencing widespread community discussion or media coverage, a public exploit (EDB-51533) exists, indicating a potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.1CPE matchmatch criteria | cpe:2.3:a:wp_sticky_social_project:wp_sticky_social:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.