WordPress Plugin Vulnerabilities
MDTF < 1.2.8 / 2.2.8 - Arbitrary Settings Update via CSRF
Description
The plugin (Free and Pro) did not have CSRF check in place when saving its settings, allowing attackers to make a logged in admin change them
Affects Plugins
References
Classification
Type
CSRF
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ryoma Nishioka
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-07-08 (about 4 years ago)
Added
2021-07-08 (about 4 years ago)
Last Updated
2021-08-10 (about 4 years ago)