Security Advisory

CVE-2022-1695

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-06 08:51:30
Last updated 2024-08-03 00:10:03
Assigner WPScan
State PUBLISHED

Description

The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.