Lucene search

K
wpvulndbWpvulndbWPVDB-ID:383235D4-8EE4-4909-B8D9-7AFC09AA424E
HistoryMay 18, 2023 - 12:00 a.m.

Better Notifications for WP < 1.9.3 - Cross-Site Request Forgery (CSRF)

2023-05-1800:00:00
wpscan.com
7
wordpress
plugin
csrf
vulnerability

EPSS

0.001

Percentile

27.7%

The plugin does not protect its handle_actions function against CSRF attacks, allowing an unauthenticated attacker to enable or disable notifications by tricking a logged in administrator to submit a crafted request.

EPSS

0.001

Percentile

27.7%

Related for WPVDB-ID:383235D4-8EE4-4909-B8D9-7AFC09AA424E