CVE-2023-27889 Information
May 11, 2023
cve
Description
Cross-site request forgery (CSRF) vulnerability in LIQUID SPEECH BALLOON versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of a user and to perform unintended operations by having a user view a malicious page.
Reference
https://jvn.jp/en/jp/JVN99657911/ https://wordpress.org/plugins/liquid-speech-balloon/#developers
Share on: