The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public
CPE | Name | Operator | Version |
---|---|---|---|
private_files | eq | 0.40 |