WordPress Plugin Vulnerabilities

bbPress Members Only < 1.3.1 - CSRF on Optional Settings page

Description

The plugin does not prevent Cross-Site Request Forgery attacks on its 'Optional Settings' page.

Proof of Concept

Affects Plugins

Fixed in 1.3.1

References

Classification

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2019-12-26 (about 6 years ago)
Added
2019-12-26 (about 6 years ago)
Last Updated
2019-12-26 (about 6 years ago)

Other