Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D50849AC-BBD9-4A2E-B2EE-E9B5B7A603E1
HistoryFeb 14, 2023 - 12:00 a.m.

NextGEN Gallery < 3.29 - Thumbnail Deletion via CSRF

2023-02-1400:00:00
wpscan.com
28
nextgen gallery
csrf
thumbnail deletion
attackers
logged in users
edit_post capability

EPSS

0.001

Percentile

21.4%

The plugin does not have CSRF checks when deleting Thumbnail, which could allow attackers to make logged in users with the edit_Post capability to perform such action via a CSRF attack

EPSS

0.001

Percentile

21.4%

Related for WPVDB-ID:D50849AC-BBD9-4A2E-B2EE-E9B5B7A603E1