Vulnerability Details CVE-2023-2495
The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.5%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-2495
-
cpe:2.3:a:greeklish-permalink_project:greeklish-permalink:1.0
-
cpe:2.3:a:greeklish-permalink_project:greeklish-permalink:1.1
-
cpe:2.3:a:greeklish-permalink_project:greeklish-permalink:2.0
-
cpe:2.3:a:greeklish-permalink_project:greeklish-permalink:3.0
-
cpe:2.3:a:greeklish-permalink_project:greeklish-permalink:3.1
-
cpe:2.3:a:greeklish-permalink_project:greeklish-permalink:3.2
-
cpe:2.3:a:greeklish-permalink_project:greeklish-permalink:3.3