MailPress <= 7.2.1 - Cross-Site Request Forgery
mediumThe MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks
- CVSS:
- 6.1
- Affected:
- up to 7.2.1
- Fix:
- No patched version reported
- Disclosed:
- May 31, 2022