Vulnerability Details CVE-2023-0832
The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the install_weglot function called via the admin_action_install_weglot action. This makes it possible for unauthenticated attackers to perform an unauthorized install of the Weglot Translate plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.8%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-0832
-
cpe:2.3:a:webfactoryltd:under_construction:-
-
cpe:2.3:a:webfactoryltd:under_construction:1.10
-
cpe:2.3:a:webfactoryltd:under_construction:1.15
-
cpe:2.3:a:webfactoryltd:under_construction:1.20
-
cpe:2.3:a:webfactoryltd:under_construction:1.22
-
cpe:2.3:a:webfactoryltd:under_construction:1.24
-
cpe:2.3:a:webfactoryltd:under_construction:1.25
-
cpe:2.3:a:webfactoryltd:under_construction:1.30
-
cpe:2.3:a:webfactoryltd:under_construction:1.35
-
cpe:2.3:a:webfactoryltd:under_construction:1.40
-
cpe:2.3:a:webfactoryltd:under_construction:1.45
-
cpe:2.3:a:webfactoryltd:under_construction:1.51
-
cpe:2.3:a:webfactoryltd:under_construction:1.55
-
cpe:2.3:a:webfactoryltd:under_construction:1.60
-
cpe:2.3:a:webfactoryltd:under_construction:1.66
-
cpe:2.3:a:webfactoryltd:under_construction:1.70
-
cpe:2.3:a:webfactoryltd:under_construction:1.75
-
cpe:2.3:a:webfactoryltd:under_construction:1.80
-
cpe:2.3:a:webfactoryltd:under_construction:1.85
-
cpe:2.3:a:webfactoryltd:under_construction:1.90
-
cpe:2.3:a:webfactoryltd:under_construction:1.96
-
cpe:2.3:a:webfactoryltd:under_construction:2.0
-
cpe:2.3:a:webfactoryltd:under_construction:2.05
-
cpe:2.3:a:webfactoryltd:under_construction:2.10
-
cpe:2.3:a:webfactoryltd:under_construction:2.15
-
cpe:2.3:a:webfactoryltd:under_construction:2.20
-
cpe:2.3:a:webfactoryltd:under_construction:2.25
-
cpe:2.3:a:webfactoryltd:under_construction:2.30
-
cpe:2.3:a:webfactoryltd:under_construction:2.35
-
cpe:2.3:a:webfactoryltd:under_construction:2.40
-
cpe:2.3:a:webfactoryltd:under_construction:2.45
-
cpe:2.3:a:webfactoryltd:under_construction:2.50
-
cpe:2.3:a:webfactoryltd:under_construction:2.55
-
cpe:2.3:a:webfactoryltd:under_construction:2.60
-
cpe:2.3:a:webfactoryltd:under_construction:2.65
-
cpe:2.3:a:webfactoryltd:under_construction:2.66
-
cpe:2.3:a:webfactoryltd:under_construction:2.70
-
cpe:2.3:a:webfactoryltd:under_construction:2.75
-
cpe:2.3:a:webfactoryltd:under_construction:2.80
-
cpe:2.3:a:webfactoryltd:under_construction:2.85
-
cpe:2.3:a:webfactoryltd:under_construction:2.90
-
cpe:2.3:a:webfactoryltd:under_construction:2.95
-
cpe:2.3:a:webfactoryltd:under_construction:3.0
-
cpe:2.3:a:webfactoryltd:under_construction:3.05
-
cpe:2.3:a:webfactoryltd:under_construction:3.10
-
cpe:2.3:a:webfactoryltd:under_construction:3.15
-
cpe:2.3:a:webfactoryltd:under_construction:3.20
-
cpe:2.3:a:webfactoryltd:under_construction:3.25
-
cpe:2.3:a:webfactoryltd:under_construction:3.30
-
cpe:2.3:a:webfactoryltd:under_construction:3.31
-
cpe:2.3:a:webfactoryltd:under_construction:3.35
-
cpe:2.3:a:webfactoryltd:under_construction:3.40
-
cpe:2.3:a:webfactoryltd:under_construction:3.45
-
cpe:2.3:a:webfactoryltd:under_construction:3.50
-
cpe:2.3:a:webfactoryltd:under_construction:3.55
-
cpe:2.3:a:webfactoryltd:under_construction:3.60
-
cpe:2.3:a:webfactoryltd:under_construction:3.65
-
cpe:2.3:a:webfactoryltd:under_construction:3.70
-
cpe:2.3:a:webfactoryltd:under_construction:3.75
-
cpe:2.3:a:webfactoryltd:under_construction:3.80
-
cpe:2.3:a:webfactoryltd:under_construction:3.81
-
cpe:2.3:a:webfactoryltd:under_construction:3.82
-
cpe:2.3:a:webfactoryltd:under_construction:3.83
-
cpe:2.3:a:webfactoryltd:under_construction:3.85
-
cpe:2.3:a:webfactoryltd:under_construction:3.86
-
cpe:2.3:a:webfactoryltd:under_construction:3.87
-
cpe:2.3:a:webfactoryltd:under_construction:3.88
-
cpe:2.3:a:webfactoryltd:under_construction:3.89
-
cpe:2.3:a:webfactoryltd:under_construction:3.90
-
cpe:2.3:a:webfactoryltd:under_construction:3.91
-
cpe:2.3:a:webfactoryltd:under_construction:3.92
-
cpe:2.3:a:webfactoryltd:under_construction:3.93