Browser and Operating System Finder <= 1.2 - Missing Authorization
medium
The Browser and Operating System Finder plugin for WordPress is missing authorization checks on functionality that resets the plugin's settings in versions up to, and including 1.2. This makes it possible for unauthenticated attackers to reset the plugin's settings.
- CVSS:
- 6.5
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 2, 2022
Browser and Operating System Finder <= 1.1 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors.
- CVSS:
- 8.8
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Nov 25, 2021
CVE-2021-20851 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database