Force First and Last Name as Display Name [force-first-last] < 1.2.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions.
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Nov 12, 2023
CVE-2023-28419 on NVD →
Force First and Last Name as Display Name <= 1.2 - Cross-Site Request Forgery
medium
The Force First and Last Name as Display Name plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the bulk “Update Existing Users” functionality. This makes it possible for unauthenticated attackers to modify use...
- CVSS:
- 5.4
- Affected:
- up to 1.2
- Fixed in:
- 1.2.1
- Disclosed:
- Mar 16, 2023
CVE-2023-28419 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database