Medium severity6.5NVD Advisory· Published Jan 17, 2024· Updated Jun 17, 2026
CVE-2023-5006
CVE-2023-5006
Description
The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <2.5.1
- cpe:2.3:a:sarveshmrao:wp_discord_invite:*:*:*:*:*:wordpress:*:*Range: <2.5.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/d29bcc1c-241b-4867-a0c8-4ae5f9d1c8e8nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.