WordPress Plugin Vulnerabilities

Kudos Donations < 3.1.2 - Arbitrary Items Deletion via CSRF

Description

The plugin has a logic flaw in its CSRF checks when deleting items such as Donors, Transactions, Subscriptions etc, allowing attackers to make a logged in admin delete them

Proof of Concept

Affects Plugins

Fixed in 3.1.2

Classification

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-11-22 (about 4 years ago)
Added
2021-11-22 (about 4 years ago)
Last Updated
2021-11-22 (about 4 years ago)

Other