Lucene search

K
wpvulndbDaniel RufWPVDB-ID:E025F821-81C3-4072-A89E-A5B3D0FB1275
HistoryMay 30, 2022 - 12:00 a.m.

CaPa Protect <= 0.5.8.2 - Arbitrary Settings Update via CSRF

2022-05-3000:00:00
Daniel Ruf
wpscan.com
11
plugin
csrf
attack
settings
protection

EPSS

0.001

Percentile

26.3%

The plugin does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable the applied protection.

PoC

EPSS

0.001

Percentile

26.3%

Related for WPVDB-ID:E025F821-81C3-4072-A89E-A5B3D0FB1275