WordPress Plugin Vulnerabilities

Multiple Plugins - CSRF Nonce Bypasses

Description

Multiple plugins did not properly check for CRSF nonces, allowing attackers to make logged in users do unwanted actions with crafted requests not containing the related nonce parameter.

Other plugins reported in the original advisory which are not here have been added individually in the last weeks

Affects Plugins

Fixed in 1.14.8.1
Fixed in 3.2.1
Fixed in 2.4.6.1
Fixed in 1.8.1
Fixed in 1.7.5
Fixed in 2.4.10
Fixed in 4.4.7

References

Classification

Miscellaneous

Original Researcher
Jerome Bruandet (nintechnet.com)
Verified
Yes

Timeline

Publicly Published
2021-03-01 (about 5 years ago)
Added
2021-03-01 (about 5 years ago)
Last Updated
2023-07-12 (about 2 years ago)

Other