1 results (0.008 seconds)
CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0
CVE-2024-0428 – Index Now <= 2.6.3 - Cross-Site Request Forgery via reset_form
https://notcve.org/view.php?id=CVE-2024-0428
12 Jan 2024 — The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing or incorrect nonce validation on the 'reset_form' function. This makes it possible for unauthenticated attackers to delete arbitrary site options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. El complemento Index Now para WordPress es vulnerable a Cross-Site Request Forgery en todas las vers... • https://plugins.trac.wordpress.org/changeset/3020958/mihdan-index-now/tags/2.6.4/src/Views/WPOSA.php • CWE-352: Cross-Site Request Forgery (CSRF) •