WordPress Plugin Vulnerabilities

MAZ Loader < 1.4.1 - Arbitrary Loader Deletion via CSRF

Description

The plugin does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack

The vendor has been notified on August 24th, 2021, as well as escalated to the WP plugins team 3 times, no fix was made despite two new versions being released.

Proof of Concept

Affects Plugins

Fixed in 1.4.1

References

Classification

Miscellaneous

Original Researcher
apple502j
Submitter
apple502j
Verified
Yes

Timeline

Publicly Published
2021-10-25 (about 4 years ago)
Added
2021-10-25 (about 4 years ago)
Last Updated
2022-04-16 (about 3 years ago)

Other