Zendesk Support for WordPress [zendesk] < 1.8.5
unknown
[en] Missing Authorization vulnerability in Zendesk Zendesk Support for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zendesk Support for WordPress: from n/a through 1.8.4.
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- Dec 9, 2024
CVE-2023-23716 on NVD →
Zendesk Support for WordPress <= 1.8.4 - Cross-Site Request Forgery
medium
The Zendesk Support for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.4. This is due to missing nonce validation on an unknown function. This makes it possible for unauthenticated attackers to invoke the functions via a forged request granted they can t...
- CVSS:
- 4.3
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.5
- Disclosed:
- Apr 18, 2023
CVE-2023-23716 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database