Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B3E97A48-1EDD-4AA8-B654-F9B8263714E0
HistoryNov 22, 2022 - 12:00 a.m.

All-In-One Security < 5.1.1 - Bulk Actions via CSRF

2022-11-2200:00:00
wpscan.com
8
all-in-one security
csrf
bulk actions
admins
attackers
manipulation

EPSS

0.001

Percentile

32.3%

The plugin does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as delete arbitrary blocked IPs) via CSRF attacks

EPSS

0.001

Percentile

32.3%

Related for WPVDB-ID:B3E97A48-1EDD-4AA8-B654-F9B8263714E0