WordPress Plugin Vulnerabilities
Unauthorised AJAX Calls via Freemius
Description
The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.
Proof of Concept
Affects Plugins
Affects Themes
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-02-28 (about 3 years ago)
Added
2022-02-28 (about 3 years ago)
Last Updated
2024-10-28 (about 1 year ago)