AF Companion <= 1.1.2 - Cross-Site Request Forgery
mediumThe AF Companion plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.1.0 to 1.1.2. This is due to missing or incorrect nonce validation on the aftc_install_activate_plugins action. This makes it possible for unauthenticated attackers to to enable or disable arbitrary plugins via a forged requ...
- CVSS:
- 5.4
- Affected:
- 1.1.0 – 1.1.2
- Fixed in:
- 1.2.0
- Disclosed:
- Dec 27, 2021