Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3767-6mf5-hjrv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues

The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues

EPSS

Процентиль: 27%
0.00099
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues

EPSS

Процентиль: 27%
0.00099
Низкий

Дефекты

CWE-352