WordPress Plugin Vulnerabilities
bbPress Members Only < 1.3.1 - CSRF on Optional Settings page
Description
The plugin does not prevent Cross-Site Request Forgery attacks on its 'Optional Settings' page.
Proof of Concept
Affects Plugins
References
Classification
Type
CSRF
OWASP top 10
CWE
Miscellaneous
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2019-12-26 (about 6 years ago)
Added
2019-12-26 (about 6 years ago)
Last Updated
2019-12-26 (about 6 years ago)