Lucene search

K
wpvulndbWpvulndbWPVDB-ID:BBEB7D96-8938-4C5A-8460-B9C2464BCDF4
HistoryFeb 15, 2023 - 12:00 a.m.

Podlove Subscribe button < 1.3.9 - Multiple CSRF

2023-02-1500:00:00
wpscan.com
6
podlove subscribe button
csrf
vulnerability
software security

0.001 Low

EPSS

Percentile

27.6%

The plugin does not have CSRF checks in some places, which could allow attackers to make logged in admins perform unwanted actions (such as create/update/delete buttons, as well update/create formats) via CSRF attacks

CPENameOperatorVersion
podlove-subscribe-buttonlt1.3.9

0.001 Low

EPSS

Percentile

27.6%

Related for WPVDB-ID:BBEB7D96-8938-4C5A-8460-B9C2464BCDF4