Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2387
HistoryNov 07, 2022 - 10:15 a.m.

Cross site request forgery (csrf)

2022-11-0710:15:00
PRIOn knowledge base
www.prio-n.com
7
csrf protection
easy digital downloads
wordpress plugin
payment history
admin
csrf attack

4.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.9%

The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack

CPENameOperatorVersion
easy_digital_downloadslt3.0

4.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.9%

Related for PRION:CVE-2022-2387