Change Table Prefix <= 2.0 - Cross-Site Request Forgery via change_prefix_form
highThe Change Table Prefix plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing or incorrect nonce validation on the 'change_prefix_form' function. This makes it possible for unauthenticated attackers to toggle maintenance mode via a forged request...
- CVSS:
- 7.1
- Affected:
- up to 2.0
- Fixed in:
- 3.0
- Disclosed:
- Feb 20, 2024