Lucene search

K
wpvulndbBob MatyasWPVDB-ID:481A376B-55BE-4AFA-94F5-C3CF8A88B8D1
HistoryMar 25, 2024 - 12:00 a.m.

NPS computy < 2.7.6 - Results Deletion via CSRF

2024-03-2500:00:00
Bob Matyas
wpscan.com
4
nps computy plugin
version 2.7.6
csrf vulnerability
results deletion
logged in users
admin
poll responses

9.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PoC

Make a logged in admin open the following: The result is that all existing poll responses are deleted.

CPENameOperatorVersion
eq2.7.6

9.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:481A376B-55BE-4AFA-94F5-C3CF8A88B8D1