Lucene search

K
wpvulndbBob MatyasWPVDB-ID:C59A8B49-6F3E-452B-BA9B-50B80C522EE9
HistoryApr 24, 2024 - 12:00 a.m.

HL Twitter <= 2014.1.18 - Unlink Twitter Account via CSRF

2024-04-2400:00:00
Bob Matyas
wpscan.com
7
csrf
vulnerability
unlinking accounts
security
software

AI Score

6.3

Confidence

High

EPSS

0

Percentile

9.0%

Description The plugin does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack

PoC

Make an admin open an HTML file containing: The Twitter connection will be removed (API tokens reset to '')

AI Score

6.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:C59A8B49-6F3E-452B-BA9B-50B80C522EE9