Lucene search

K
patchstackMuhammad Daffa (Patchstack Alliance)PATCHSTACK:0D14EC0AF092EF9773789F78D3EB4F36
HistoryOct 28, 2022 - 12:00 a.m.

WordPress Creative Mail plugin <= 1.5.4 - Cross-Site Request Forgery (CSRF) vulnerability

2022-10-2800:00:00
Muhammad Daffa (Patchstack Alliance)
patchstack.com
21
wordpress
creative mail plugin
cross-site request forgery
csrf
vulnerability
settings reset
patchstack alliance
update

0.001 Low

EPSS

Percentile

32.3%

Cross-Site Request Forgery (CSRF) vulnerability leading to plugin settings reset discovered by Muhammad Daffa (Patchstack Alliance) in the WordPress Creative Mail plugin (versions <= 1.5.4).

Solution

           Update the WordPress Creative Mail plugin to the latest available version (at least 1.6.0).
CPENameOperatorVersion
creative maille1.5.4

0.001 Low

EPSS

Percentile

32.3%

Related for PATCHSTACK:0D14EC0AF092EF9773789F78D3EB4F36