Lucene search

K
patchstackRyoma NishiokaPATCHSTACK:C8FA700DFFACEC687299E1E1A68B007D
HistoryJul 26, 2021 - 12:00 a.m.

WordPress Admin Custom Login plugin <= 3.2.7 – Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS)

2021-07-2600:00:00
Ryoma Nishioka
patchstack.com
5

0.001 Low

EPSS

Percentile

47.3%

Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) discovered by Ryoma Nishioka (Cryptography Laboratory - Tokyo Denki University) in WordPress Admin Custom Login plugin (versions <= 3.2.7).

Solution

           Update the WordPress Admin Custom Login plugin to the latest available version (at least 3.2.8).
CPENameOperatorVersion
admin custom loginle3.2.7

0.001 Low

EPSS

Percentile

47.3%

Related for PATCHSTACK:C8FA700DFFACEC687299E1E1A68B007D