Security Advisory

CVE-2022-1694

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-13 12:42:25
Last updated 2024-08-03 00:10:03
Assigner WPScan
State PUBLISHED

Description

The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.