Bulk Page Creator <= 1.1.3 - Cross-Site Request Forgery to Arbitrary Page Creation
highThe Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- May 9, 2022