CVE detail
CVE-2023-2495 — CVE-2023-2495
Published 2023-07-10 · Modified 2026-06-17 · Vendor greeklish-permalink_project · Product greeklish-permalink · Source nvd
MEDIUM
severity
CVSS-derived band
0.0027
EPSS probability
exploitation probability, 30d
19.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References