WordPress Plugin Vulnerabilities

MDTF < 1.2.8 / 2.2.8 - Arbitrary Settings Update via CSRF

Description

The plugin (Free and Pro) did not have CSRF check in place when saving its settings, allowing attackers to make a logged in admin change them

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Ryoma Nishioka
Verified
Yes

Timeline

Publicly Published
2021-07-08 (about 4 years ago)
Added
2021-07-08 (about 4 years ago)
Last Updated
2021-08-10 (about 4 years ago)

Other