Medium severity4.3NVD Advisory· Published Nov 3, 2023· Updated Jun 17, 2026
CVE-2023-5945
CVE-2023-5945
Description
The video carousel slider with lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the responsive_video_gallery_with_lightbox_video_management_func() function. This makes it possible for unauthenticated attackers to delete videos hosted from the video slider via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=1.0
- nik00726/video carousel slider with lightboxv5Range: 1.0
Patches
Vulnerability mechanics
References
3- plugins.trac.wordpress.org/browser/wp-responsive-video-gallery-with-lightbox/tags/1.0.1/wp-responsive-video-gallery-with-lightbox.phpnvdPatchThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/dc052b00-65a7-4668-8bdd-b06d69d12a4anvdPatchThird Party Advisory
- github.com/wp-plugins/wp-responsive-video-gallery-with-lightbox/blob/master/wp-responsive-video-gallery-with-lightbox.phpnvdExploit
News mentions
0No linked articles in our index yet.