WordPress Plugin Vulnerabilities

XootiX Plugins - Various Versions CSRF to Arbitrary Options Update

Description

The plugins Login/Signup Popup, Side Cart Woocommerce, and Waitlist Woocommerce are all vulnerable to cross-site request forgery due to a missing nonce check that would make it possible for attackers to update arbitrary options on a vulnerable WordPress site.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-01-13 (about 4 years ago)
Added
2022-01-13 (about 4 years ago)
Last Updated
2022-04-13 (about 3 years ago)

Other