Generated remediation guidance and an executive summary. No account required.
The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for unauthenticated attackers to delete post meta information and reset network access tokens, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Use Warfareplugins vendor hub and Social Warfare product page to widen CVE-2023-0403 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-9978, CVE-2021-4434 and CVE-2023-4842 for nearby disclosures in the same product family.