Lucene search

K
wpvulndbBob MatyasWPVDB-ID:A3C282FB-81B8-48BF-8C18-8366EA8AD9AF
HistoryApr 11, 2024 - 12:00 a.m.

Button Generator < 3.0 - Button Deletion via CSRF

2024-04-1100:00:00
Bob Matyas
wpscan.com
4
button generator
csrf attack
admin
bulk deletion
plugin vulnerability

AI Score

6.3

Confidence

High

EPSS

0

Percentile

9.0%

Description The plugin does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

PoC

Make a logged in admin open an HTML file containing: action

AI Score

6.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:A3C282FB-81B8-48BF-8C18-8366EA8AD9AF