CVE-2023-6946

CVE-2023-6946: Autotitle for WordPress <= 1.0.3 - Settings Update to Stored XSS via CSRF

Vendor Unknown
Product Autotitle for WordPress
Published January 29, 2024
Last update June 11, 2025

CVSS base score

—

What the vulnerability does

01Description

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Key dates

02Disclosure timeline

January 29, 2024 CVE published
June 11, 2025 Record updated