The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF at…
Medium CVSS 5.5
Summary
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://wpscan.com/vulnerability/749ae334-b1d1-421e-a04c-35464c961a4a/ Exploit
- https://wpscan.com/vulnerability/749ae334-b1d1-421e-a04c-35464c961a4a/ Exploit
Timeline
- nvd_ingest NVD