Custom Simple RSS < 2.0.7 - Cross-Site Request Forgery
mediumA CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.
- CVSS:
- 6.5
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Jul 27, 2019