Lucene search

K
wpvulndbWpvulndbWPVDB-ID:FA6C8017-8385-4C10-AF30-0A2E07E8A52B
HistoryDec 08, 2023 - 12:00 a.m.

Button Generator – easily Button Builder < 2.3.9 - Cross-Site Request Forgery

2023-12-0800:00:00
wpscan.com
5
button generator
cross-site request forgery
wordpress
missing nonce validation
unauthenticated attackers
security vulnerability

8.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.1%

Description The Button Generator – easily Button Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.8. This is due to missing nonce validation on the btg_count() function. This makes it possible for unauthenticated attackers to reset the button counter via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

8.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.1%

Related for WPVDB-ID:FA6C8017-8385-4C10-AF30-0A2E07E8A52B