CVE-2023-0335: Wpvar Wp Shamsi

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.

Affected products

  • Wpvar Wp Shamsi: up to and including 4.3.3

Published 2023-03-27. Last modified 2026-06-17.