Fileviewer <= 2.2 - Cross-Site Request Forgery
highThe Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload and delete files. As a result, attackers could make a logged in administrator delete and upload arbitrary files via a CSRF attack
- CVSS:
- 8.8
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 17, 2021