Lucene search

K
wpvulndbWpvulndbWPVDB-ID:1543BB1F-8A5C-4865-98C5-25C20C736C3C
HistoryAug 12, 2019 - 12:00 a.m.

WP Social Feed Gallery < 2.4.8 - CSRF & Missing Authorisation Checks

2019-08-1200:00:00
wpscan.com
9

0.001 Low

EPSS

Percentile

30.9%

The lack of CSRF and Authorisations checks in some AJAX methods, such as qligg_dismiss_notice and qligg_form_item_delete could allow attacker to perform unauthorised actions via actions when logged in as a low privilege user, or via CSRF attacks.

CPENameOperatorVersion
insta-gallerylt2.4.8

0.001 Low

EPSS

Percentile

30.9%

Related for WPVDB-ID:1543BB1F-8A5C-4865-98C5-25C20C736C3C