Dynamic Content for Elementor < 2.12.5 - Cross-Site Request Forgery
mediumThe Dynamic Content for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.12.5. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted th...
- CVSS:
- 4.3
- Affected:
- up to 2.12.5
- Fixed in:
- 2.12.5
- Disclosed:
- Dec 28, 2023