WordPress Plugin Vulnerabilities
Private Messages For WordPress <= 2.1.10 - Arbitrary Message Sent via CSRF
Description
The plugin does not have CSRF in place when sending messages, allowing attackers user sent arbitrary message on their behalf via a CSRF attack
Affects Plugins
References
CVE
Classification
Type
CSRF
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
BEE-K
Verified
No
WPVDB ID
Timeline
Publicly Published
2022-05-25 (about 3 years ago)
Added
2022-06-16 (about 3 years ago)
Last Updated
2023-03-18 (about 3 years ago)