cleantalk
Vulnerabilities and Security Researches

Custom Post Type UI, CVE-2023-1623

CVE, Research URL

CVE-2023-1623

Application

Custom Post Type UI

Published on
Apr 25, 2023
Research Description
The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.
Affected versions
max 1.13.5.
Status
vulnerable