Lucene search

K
wpvulndbWpvulndbWPVDB-ID:EB9F67B9-1956-4485-A007-1EB932288200
HistoryMay 18, 2023 - 12:00 a.m.

UpdraftPlus < 1.23.4 - CSRF

2023-05-1800:00:00
wpscan.com
3
updraftplus
csrf
vulnerability
version 1.23.4
software
authentication
javascript
admin

0.0005 Low

EPSS

Percentile

17.4%

The plugin does not have CSRF check in the action_authenticate_storage, which could allow attackers to make logged in admins inject JavaScript into a parameter in the authentication process via a CSRF attack when they can trick an admin to perform multiple actions including re-authenticating a connection to a storage.

CPENameOperatorVersion
updraftpluslt1.23.4

0.0005 Low

EPSS

Percentile

17.4%

Related for WPVDB-ID:EB9F67B9-1956-4485-A007-1EB932288200