WordPress Plugin Vulnerabilities

MZ Mindbody API < 2.8.3 - Unauthorised AJAX Calls

Description

The plugin did not properly check for CSRF and authorisation in various AJAX actions, allowing attacker to make users call them and perform unwanted actions, as well as allow low privilege users to call them

Proof of Concept

Affects Plugins

Fixed in 2.8.3

Classification

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-06-30 (about 4 years ago)
Added
2021-06-30 (about 4 years ago)
Last Updated
2021-06-30 (about 4 years ago)

Other