Описание
The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible for attackers to conduct CSRF attacks. This could allow attackers to disable the plugin's protections.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.2 (включая)
cpe:2.3:a:laubrotel:lbstopattack:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 35%
0.00144
Низкий
6.5 Medium
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
The LBStopAttack WordPress plugin through 1.1.2 does not use nonces when saving its settings, making it possible for attackers to conduct CSRF attacks. This could allow attackers to disable the plugin's protections.
EPSS
Процентиль: 35%
0.00144
Низкий
6.5 Medium
CVSS3