Lucene search

K
wpvulndbApple502jWPVDB-ID:DCBCF6E7-E5B3-498B-9F5E-7896D309441F
HistorySep 15, 2021 - 12:00 a.m.

Compact WP Audio Player < 1.9.7 - Setting Change via CSRF

2021-09-1500:00:00
apple502j
wpscan.com
11
wp audio player
csrf
vulnerability
setting change

EPSS

0.001

Percentile

27.4%

The plugin does not implement nonce checks, which could allow attackers to make a logged in admin change the “Disable Simultaneous Play” setting via a CSRF attack.

PoC

EPSS

0.001

Percentile

27.4%

Related for WPVDB-ID:DCBCF6E7-E5B3-498B-9F5E-7896D309441F