WordPress Plugin Vulnerabilities

Images to WebP < 1.9 - Multiple Cross Site Request Forgery (CSRF)

Description

The plugin does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion

Proof of Concept

Affects Plugins

Fixed in 1.9

References

Classification

Miscellaneous

Original Researcher
apple502j
Submitter
apple502j
Verified
Yes

Timeline

Publicly Published
2021-10-19 (about 4 years ago)
Added
2021-10-19 (about 4 years ago)
Last Updated
2022-04-11 (about 3 years ago)

Other