DX Share Selection <= 1.4 - Cross-Site Request Forgery to Cross-Site Scripting
highThe DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the dxss_admin_page() function found in the ~/dx-share-selection.php file. This makes it possible for unauthenticated attackers to inject malicious web...
- CVSS:
- 8.8
- Affected:
- up to 1.4
- Fixed in:
- 1.5
- Disclosed:
- Jun 22, 2022