The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 14 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: WPScan
Published: 2023-03-27T15:37:37.404Z
Updated: 2025-02-14T16:03:20.951Z
Reserved: 2023-01-25T10:07:14.356Z
Link: CVE-2023-0496
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T05:10:56.333Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-03-27T16:15:08.560
Modified: 2025-02-14T16:15:32.377
Link: CVE-2023-0496
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow