Lucene search

K
wpvulndbDmitriiWPVDB-ID:B2C6FA7D-1B0F-444B-8CA5-8C1C06CEA1D9
HistoryAug 07, 2023 - 12:00 a.m.

POEditor < 0.9.8 - Settings Reset via CSRF

2023-08-0700:00:00
Dmitrii
wpscan.com
3
poeditor
csrf
vulnerability
admin
settings
reset
api key
attack

AI Score

7

Confidence

High

EPSS

0.001

Percentile

30.2%

Description The plugin does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset the plugin’s settings and update its API key via CSRF attacks.

PoC

AI Score

7

Confidence

High

EPSS

0.001

Percentile

30.2%

Related for WPVDB-ID:B2C6FA7D-1B0F-444B-8CA5-8C1C06CEA1D9