CVE-2023-41670 – WordPress Use Memcached Plugin <= 1.0.5 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-41670
04 Sep 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Palasthotel (in person: Edward Bock) Use Memcached plugin <= 1.0.4 versions. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Palasthotel (en persona: Edward Bock) Utilice el complemento Memcached en versiones <= 1.0.4. The Use Memcached plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing nonce validation on the save_settings() function hooked via 'admin_init'. This makes ... • https://patchstack.com/database/vulnerability/use-memcached/wordpress-use-memcached-plugin-1-0-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •