WordPress Plugin Vulnerabilities

Private Messages For WordPress <= 2.1.10 - Arbitrary Message Sent via CSRF

Description

The plugin does not have CSRF in place when sending messages, allowing attackers user sent arbitrary message on their behalf via a CSRF attack

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
BEE-K
Verified
No

Timeline

Publicly Published
2022-05-25 (about 3 years ago)
Added
2022-06-16 (about 3 years ago)
Last Updated
2023-03-18 (about 3 years ago)

Other