WordPress Plugin Vulnerabilities
Multiple Plugins from Cool Plugins - Subscriber+ Arbitrary Plugin Installation & Activation
Description
Multiple plugins from the Cool Plugins vendor are missing capability and proper CSRF check in the cool_plugins_install and cool_plugins_activate AJAX actions, available to any authenticated users, allowing them to install and activate arbitrary plugins via an archive hosted on a remote server they control
Affects Plugins
References
Classification
Type
RCE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Jerome Bruandet (nintechnet)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-04-12 (about 4 years ago)
Added
2022-04-12 (about 4 years ago)
Last Updated
2023-06-08 (about 2 years ago)