Lucene search

K
wpvulndb0xB9WPVDB-ID:C9911236-4AF3-4557-9BC0-217FACE534E1
HistoryApr 12, 2021 - 12:00 a.m.

Business Directory Plugin < 5.11.2 - Arbitrary Payment History Update

2021-04-1200:00:00
0xB9
wpscan.com
7

EPSS

0.001

Percentile

27.4%

The plugin suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)

PoC

Add a listing, don’t complete payment (status will be pending) payment[created_at_date]|
—|—
payment[created_at_time_hour]|
payment[created_at_time_min]|
payment[id]|
payment[payer_data][address]|
payment[payer_data][address_2]|
payment[payer_data][city]|
payment[payer_data][country]|
payment[payer_data][state]|
payment[payer_data][zip]|
payment[payer_email]|
payment[payer_first_name]|
payment[payer_last_name]|
payment[status]|
payment_note|

EPSS

0.001

Percentile

27.4%

Related for WPVDB-ID:C9911236-4AF3-4557-9BC0-217FACE534E1