Classic Editor Addon < 2.6.4 - Cross-Site Request Forgery
highThe Classic Editor Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.3. This is due to inclusion of a vulnerable version of the wp-dependency-installer library. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins via a...
- CVSS:
- 8.8
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Jan 24, 2022