Lucene search

K
wpvulndbWpvulndbWPVDB-ID:F2B8DD08-6661-41DA-B1C4-FE001EE268D3
HistoryJul 28, 2023 - 12:00 a.m.

Multiple Plugins from Inisev - Plugin Installation via CSRF

2023-07-2800:00:00
wpscan.com
7
inisev
csrf attack
plugin installation
security vulnerability
software

4.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.3%

Description Multiple plugins from the Inisev vendor are lacking CSRF check in the handle_installation function hooked to the inisev_installation AJAX action, allowing unauthenticated attackers to make logged in admins install plugins from Inisev on the blog via a CSRF attack

4.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.3%

Related for WPVDB-ID:F2B8DD08-6661-41DA-B1C4-FE001EE268D3