EasyRecipe <= 3.5.3251 - Cross-Site Request Forgery
mediumThe EasyRecipe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3251. This is due to missing nonce validation on several functions such as the saveStyle() and updateCustomCSS() functions. This makes it possible for unauthenticated attackers to modify several of the...
- CVSS:
- 4.3
- Affected:
- up to 3.5.3251
- Fix:
- No patched version reported
- Disclosed:
- Oct 26, 2023