Duplicate Page or Post <= 1.5.0 - Missing Authorization to Stored Cross-Site Scripting
mediumThe Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Further...
- CVSS:
- 6.4
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.1
- Disclosed:
- Jan 24, 2022