WordPress Plugin Vulnerabilities

WP Customer Area < 8.1.4 - Unauthorised Actions via CSRF

Description

The plugin does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

Proof of Concept

Affects Plugins

Fixed in 8.1.4

References

Classification

Miscellaneous

Original Researcher
rezaduty
Submitter
rezaduty
Verified
Yes

Timeline

Publicly Published
2023-01-17 (about 2 years ago)
Added
2023-01-17 (about 2 years ago)
Last Updated
2023-01-18 (about 2 years ago)

Other