KONTXT Improves WordPress Search <= 1.4.6 - Cross-Site Request Forgery
highThe KONTXT Improves WordPress Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to read data such as an API key via a forged requ...
- CVSS:
- 8.8
- Affected:
- up to 1.4.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 30, 2021