Lucene search

K
wpexploitSushmita PoudelWPEX-ID:51D0311A-673B-4538-9427-A48E8C89E38B
HistoryJun 12, 2024 - 12:00 a.m.

Himer - Social Questions and Answers < 2.1.1 - Multiple CSRF on the Group Section

2024-06-1200:00:00
Sushmita Poudel
25
himer
social q&a
2.1.1
multiple csrf
group section
exploit
june 26 2024
update.

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

17.1%

Description The theme does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group invitations or leaving a group

The PoC will be displayed on June 26, 2024, to give users the time to update.

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

17.1%

Related for WPEX-ID:51D0311A-673B-4538-9427-A48E8C89E38B