Beveiligingsadvies

CVE-2024-4969

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-06-21 06:00:05
Laatst bijgewerkt 2024-08-01 20:55:10
Toegewezen door WPScan
CVSS-score 4.3
Status PUBLISHED

Beschrijving

The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack