Lucene search

K
wpvulndbWpvulndbWPVDB-ID:31677623-DE4F-4F5E-9360-D8D066760EBC
HistoryNov 14, 2022 - 12:00 a.m.

WP Affiliate Platform < 6.4.0 - Affiliate Record Deletion via CSRF

2022-11-1400:00:00
wpscan.com
5
wordpress
affiliate
platform
record deletion
csrf
attackers
admins

EPSS

0.001

Percentile

23.6%

The plugin does not have CSRF checks when deleting affiliate records, which could allow attackers to make logged in admins to delete arbitrary record via a CSRF attack

EPSS

0.001

Percentile

23.6%

Related for WPVDB-ID:31677623-DE4F-4F5E-9360-D8D066760EBC