Lucene search

K
wpexploitApple502jWPEX-ID:519205FF-2FF6-41E4-9E95-475AB2CE35B9
HistoryOct 25, 2021 - 12:00 a.m.

MAZ Loader < 1.4.1 - Arbitrary Loader Deletion via CSRF

2021-10-2500:00:00
apple502j
347
maz loader
csrf vulnerability
arbitrary deletion

EPSS

0.001

Percentile

27.6%

The plugin does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack The vendor has been notified on August 24th, 2021, as well as escalated to the WP plugins team 3 times, no fix was made despite two new versions being released.

https://example.com/wp-admin/admin.php?page=maz-loader-list&action=delete&id=1

EPSS

0.001

Percentile

27.6%

Related for WPEX-ID:519205FF-2FF6-41E4-9E95-475AB2CE35B9