{"api_version":"1","generated_at":"2026-07-24T19:44:35+00:00","cve":"CVE-2023-4307","urls":{"html":"https://cve.report/CVE-2023-4307","api":"https://cve.report/api/cve/CVE-2023-4307.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-4307","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-4307"},"summary":{"title":"CVE-2023-4307","description":"The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2023-09-11 20:15:00","updated_at":"2023-11-07 04:22:00"},"problem_types":[],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/06f7aa45-b5d0-4afb-95cc-8f1c82f6f8b3","name":"https://wpscan.com/vulnerability/06f7aa45-b5d0-4afb-95cc-8f1c82f6f8b3","refsource":"MISC","tags":[],"title":"Lock User Account <= 1.0.3 - Arbitrary Account Lock/Unlock via CSRF WordPress Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-4307","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4307","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"4307","vulnerable":"1","versionEndIncluding":"1.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"teknigar","cpe5":"lock_user_account","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-4307","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-352 Cross-Site Request Forgery (CSRF)"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Lock User Account","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"versions":[{"status":"affected","versionType":"custom","version":"0","lessThanOrEqual":"1.0.3"}],"defaultStatus":"affected"}}]}}]}}]}},"references":{"reference_data":[{"url":"https://wpscan.com/vulnerability/06f7aa45-b5d0-4afb-95cc-8f1c82f6f8b3","refsource":"MISC","name":"https://wpscan.com/vulnerability/06f7aa45-b5d0-4afb-95cc-8f1c82f6f8b3"}]},"generator":{"engine":"WPScan CVE Generator"},"source":{"discovery":"EXTERNAL"},"credits":[{"lang":"en","value":"Dmitrii Ignatyev"},{"lang":"en","value":"WPScan"}]},"nvd":{"publishedDate":"2023-09-11 20:15:00","lastModifiedDate":"2023-11-07 04:22:00","problem_types":[],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:teknigar:lock_user_account:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"1.0.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}