Lucene search

K
wpvulndbWpvulndbWPVDB-ID:C750E6F1-E716-4053-84F5-0501D6B93F93
HistoryNov 03, 2022 - 12:00 a.m.

VR Calendar < 2.3.4 - Calendar Deletion/Update & Settings Update via CSRF

2022-11-0300:00:00
wpscan.com
6
vr calendar
plugin
csrf

0.001 Low

EPSS

Percentile

38.7%

The plugin does not have CSRF checks when deleting and updating calendars, as well as updating the plugin settings, which could allow attackers to make logged a admin delete and update arbitrary calendars and modify the plugin settings via CSRF attacks

CPENameOperatorVersion
vr-calendar-synclt2.3.4

0.001 Low

EPSS

Percentile

38.7%

Related for WPVDB-ID:C750E6F1-E716-4053-84F5-0501D6B93F93