WordPress Plugin Vulnerabilities

Thumbnail Slider With Lightbox < 1.0.1 - Arbitrary File Upload via CSRF

Description

The plugin does not have CSRF check in the addedit feature, which could allow attackers to make logged in admins upload arbitrary files via a CSRF attack

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Ala Arfaoui
Verified
No

Timeline

Publicly Published
2023-10-26 (about 2 years ago)
Added
2023-11-17 (about 2 years ago)
Last Updated
2023-11-17 (about 2 years ago)

Other