Lucene search

K
wpvulndbWpvulndbWPVDB-ID:77A45D28-DCEA-4B2C-8AC3-560EE6D4A495
HistoryDec 12, 2023 - 12:00 a.m.

DoFollow Case by Case < 3.5.0 - Email&URLs Adding to Allowlist via CSRF

2023-12-1200:00:00
wpscan.com
7
dofollow
case by case
csrf
email
urls
allowlist
security
vulnerability

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

24.1%

Description The plugin does not have CSRF checks in its getEmail and getUrl functions, which could allow attackers to make logged in admins add email and URLs to the allow list via CSRF attacks

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

24.1%

Related for WPVDB-ID:77A45D28-DCEA-4B2C-8AC3-560EE6D4A495