WordPress Plugin Vulnerabilities

CSRF Bypass in Multiple Plugins

Description

Multiple plugins are affected by CSRF bypass as they do not properly check for the nonce due to a logic flaw. This could allow attackers to make logged in users do unwanted actions

Affects Plugins

No known fix
No known fix
Fixed in 1.3.2
Fixed in 1.0.9
Fixed in 1.1.2
Fixed in 1.6
Fixed in 2.8.29
Fixed in 2.1.2
Fixed in 3.5.2

References

Classification

Miscellaneous

Original Researcher
Jerome Bruandet (NinTechNet)
Verified
Yes

Timeline

Publicly Published
2021-06-08 (about 4 years ago)
Added
2021-06-08 (about 4 years ago)
Last Updated
2023-07-12 (about 2 years ago)

Other