Easy WP Cleaner <= 1.9 - Cross-Site Request Forgery
mediumThe Easy WP Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9. This is due to missing nonce validation on the easy_wp_cleaner_optimize() function. This makes it possible for unauthenticated attackers to delete data from a WordPress instance via a forged reque...
- CVSS:
- 5.4
- Affected:
- up to 1.9
- Fixed in:
- 2.0
- Disclosed:
- Sep 5, 2023