CVE-2023-6390

CVE-2023-6390: WordPress Users <= 1.4 - Settings Update via CSRF

Vendor Unknown
Product WordPress Users
Published January 29, 2024
Last update June 20, 2025

CVSS base score

—

What the vulnerability does

01Description

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Key dates

02Disclosure timeline

January 29, 2024 CVE published
June 20, 2025 Record updated