WordPress Plugin Vulnerabilities

WP Social Feed Gallery < 2.4.8 - CSRF & Missing Authorisation Checks

Description

The lack of CSRF and Authorisations checks in some AJAX methods, such as qligg_dismiss_notice and qligg_form_item_delete could allow attacker to perform unauthorised actions via actions when logged in as a low privilege user, or via CSRF attacks.

Affects Plugins

Fixed in 2.4.8

References

Miscellaneous

Timeline

Publicly Published
2019-08-12 (about 6 years ago)
Added
2019-08-29 (about 6 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other