Lucene search

K
wpvulndbWpvulndbWPVDB-ID:49FB8257-559A-4B98-83FE-52D5B7E6A27C
HistoryJan 24, 2022 - 12:00 a.m.

Access Demo Importer < 1.0.8 - Arbitrary Plugin Activation via CSRF

2022-01-2400:00:00
wpscan.com
10
access demo importer
arbitrary plugin activation
csrf
software
security vulnerability

EPSS

0.001

Percentile

21.6%

The plugin does not have CSRF check in place when activating installed plugins, which could allow an attacker to make a logged in admin perform such action via a CSRF attack

EPSS

0.001

Percentile

21.6%

Related for WPVDB-ID:49FB8257-559A-4B98-83FE-52D5B7E6A27C