KONTXT Content Advisor <= 2.2 - Cross-Site Request Forgery
highThe KONTXT Content Advisor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the blobinator_process_text function. This makes it possible for unauthenticated attackers to edit posts via a forged request granted...
- CVSS:
- 8.8
- Affected:
- up to 2.2
- Fixed in:
- 2.3
- Disclosed:
- Jun 30, 2021