Lucene search

K
wpvulndbWpvulndbWPVDB-ID:54D20241-0ED9-49BD-9857-014AC39E6608
HistoryJan 13, 2024 - 12:00 a.m.

Index Now < 2.6.4 - Cross-Site Request Forgery via reset_form

2024-01-1300:00:00
wpscan.com
5
wordpress
cross-site request forgery
index now plugin

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

28.6%

Description The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing or incorrect nonce validation on the ‘reset_form’ function. This makes it possible for unauthenticated attackers to delete arbitrary site options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

28.6%

Related for WPVDB-ID:54D20241-0ED9-49BD-9857-014AC39E6608