CVE-2023-6390

CVE-2023-6390: WordPress Users <= 1.4 - Settings Update via CSRF

Vendor Unknown
Product WordPress Users
Published January 29, 2024
Last update June 20, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Key dates

02Disclosure timeline

January 29, 2024 CVE published
June 20, 2025 Record updated