๐Ÿ” CVE Alert

CVE-2023-1604

MEDIUM 4.7

Short URL <= 1.6.8 - Cross-Site Request Forgery via configuration_page

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or incorrect nonce validation on the configuration_page function. This makes it possible for unauthenticated attackers to add and import redirects, including comments containing cross-site scripting as detailed in CVE-2023-1602, granted they can trick a site administrator into performing an action such as clicking on a link.

CWE CWE-352
Vendor kaizencoders
Product short url
Published Aug 17, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for kaizencoders short url

Be the first to know when new medium vulnerabilities affecting kaizencoders short url are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

kaizencoders / Short URL
0 โ‰ค 1.6.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/b926243c-ed12-4afe-ac72-932d4d871019?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/shorten-url/trunk/shorten-url.php#L322

Credits

Etan Imanol Castro Aldrete