CVE-2023-6946

CVE-2023-6946: Autotitle for WordPress <= 1.0.3 - Settings Update to Stored XSS via CSRF

Vendor Unknown
Product Autotitle for WordPress
Published January 29, 2024
Last update June 11, 2025

CVSS base score

What the vulnerability does

01Description

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Key dates

02Disclosure timeline

January 29, 2024 CVE published
June 11, 2025 Record updated