Security Advisory

CVE-2023-5884

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-12-04 21:29:32
Last updated 2024-08-02 08:14:24
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.