CVE-2023-0484

CVE-2023-0484: Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks < 1.1.6 - Arbitrary Plugin Activation via CSRF

Vendor Unknown
Product Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks
Published March 27, 2023
Last update February 19, 2025

CVSS base score

What the vulnerability does

01Description

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

Key dates

02Disclosure timeline

March 27, 2023 CVE published
February 19, 2025 Record updated