Lucene search

K
wpvulndbWpvulndbWPVDB-ID:7C6F05DC-1C26-4E83-816F-78EA12B4130A
HistoryJun 27, 2023 - 12:00 a.m.

Salon Booking System < 8.4.8 - User Role change via CSRF

2023-06-2700:00:00
wpscan.com
3
plugin
nonce checks
logged in admin
user role
customer

EPSS

0.002

Percentile

51.8%

The plugin does not implement nonce checks, which could allow attackers to make a logged in admin change its own user role to customer.

EPSS

0.002

Percentile

51.8%

Related for WPVDB-ID:7C6F05DC-1C26-4E83-816F-78EA12B4130A