Описание
The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.20.3 (исключая)
cpe:2.3:a:back2nature:word_balloon:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 38%
0.00164
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 6.5
github
около 2 лет назад
The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.
EPSS
Процентиль: 38%
0.00164
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-352