Google Site Verification plugin using Meta Tag <= 1.2 - Cross-Site Request Forgery
mediumThe Google Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2. This is due to missing nonce validation on the function used to update the plugin's settings. This makes it possible for unauthenticated attackers to update the plug...
- CVSS:
- 4.3
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- May 10, 2023