WordPress Plugin Vulnerabilities

Newsletter Popup <= 1.2 - List Deletion via CSRF

Description

The plugin does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack

Proof of Concept

Make an admin open a URL (where `<ID>` is a valid id):

http://example.com4/wp-admin/admin.php?page=wp_newsletter_show_items&action=trash&id=<ID>

Affects Plugins

No known fix

References

Classification

Miscellaneous

Original Researcher
Bob Matyas
Submitter
Bob Matyas
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2024-04-25 (about 2 months ago)
Added
2024-04-25 (about 2 months ago)
Last Updated
2024-04-25 (about 2 months ago)

Other