WordPress Plugin Vulnerabilities

Useful Banner Manager <= 1.6.1 - Modify banners via CSRF

Description

The plugin does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Daniel Ruf
Submitter
Daniel Ruf
Submitter website
Verified
Yes

Timeline

Publicly Published
2022-05-17 (about 3 years ago)
Added
2022-05-17 (about 3 years ago)
Last Updated
2022-05-18 (about 3 years ago)

Other