← WordPress Vulnerabilities
WordPress security by component

Custom Options Plus

Custom Options Plus is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Nov 12, 2023; the highest published CVSS base score is 5.4.

Plugin slug: custom-options-plus

CVE-2023-28420: Custom Options Plus: Cross-site request forgery

Custom Options Plus is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedNov 12, 2023
Safe version guidanceSee mitigation notes
Published vulnerabilities for custom-options-plus
Safe version
Nov 12, 2023 CVE-2023-28420
Custom Options Plus: Cross-site request forgery
Custom Options Plus is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVD8.8