Lucene search

K
wpvulndbWpvulndbWPVDB-ID:61576D1E-0F49-4EF5-837B-1E4CF8A10133
HistoryMay 24, 2023 - 12:00 a.m.

Download < 1.1.0 - Cross-Site Request Forgery

2023-05-2400:00:00
wpscan.com
4
plugin
download
csrf
vulnerability
cross-site request forgery
nonces
validation

EPSS

0.001

Percentile

28.3%

The plugin does not properly validate and verify user requests use nonces, making it susceptible to Cross-Site Request Forgery (CSRF) attacks.

EPSS

0.001

Percentile

28.3%

Related for WPVDB-ID:61576D1E-0F49-4EF5-837B-1E4CF8A10133