Custom Content by Country <= 3.1.2 - Cross-Site Request Forgery
highThe Custom Content by Country plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.2. This is due to missing or incorrect nonce validation on the handleSubmit_main function. This makes it possible for unauthenticated attackers to invoke this function, via forged request...
- CVSS:
- 8.8
- Affected:
- 3.1.2 – 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- Dec 5, 2022