CVE-2023-0495

CVE-2023-0495: HT Slider For Elementor < 1.4.0 - Arbitrary Plugin Activation via CSRF

Vendor Unknown
Product HT Slider For Elementor
Published March 27, 2023
Last update February 19, 2025

CVSS base score

What the vulnerability does

01Description

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

Key dates

02Disclosure timeline

March 27, 2023 CVE published
February 19, 2025 Record updated