WordPress Plugin Vulnerabilities
WP Social Feed Gallery < 2.4.8 - CSRF & Missing Authorisation Checks
Description
The lack of CSRF and Authorisations checks in some AJAX methods, such as qligg_dismiss_notice and qligg_form_item_delete could allow attacker to perform unauthorised actions via actions when logged in as a low privilege user, or via CSRF attacks.
Affects Plugins
References
CVE
Miscellaneous
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-08-12 (about 6 years ago)
Added
2019-08-29 (about 6 years ago)
Last Updated
2020-09-22 (about 5 years ago)