A2 Optimized WP <= 3.0.4 - Cross Site Request Forgery
mediumThe A2 Optimized WP plugin for WordPress is vulnerable to Cross Site Request Forgery due to missing nonce validation on the 'admin_pagespeed_page' function in versions up to, and including 3.0.4. This makes it possible for unauthenticated attackers to enable data collection by the plugin developer via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Feb 6, 2023