1 results (0.004 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values. El plugin QOTD de Shantz WordPress versiones hasta 1.2.2, carece de cualquier comprobación de tipo CSRF cuando actualiza su configuración, permitiendo a atacantes hacer que los administradores con sesión iniciada los cambien por valores arbitrarios. The Shantz WordPress QOTD for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2 This is due to missing or incorrect nonce validation on the function. This makes it possible for unauthenticated attackers to make logged in administrators change them to arbitrary values via a forged request. • https://wpscan.com/vulnerability/1dd0f9a8-22ab-4ecc-a925-605822739000 • CWE-352: Cross-Site Request Forgery (CSRF) •