1 results (0.006 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

05 Sep 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1 versions. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Laposta - en el complemento Roel Bousardt Laposta Signup Basic en versiones <= 1.4.1. The Laposta Signup Basic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the ajaxResetCache function. This makes it possible for una... • https://patchstack.com/database/vulnerability/laposta-signup-basic/wordpress-laposta-signup-basic-plugin-1-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •