Post Snippits <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update
mediumThe Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings page handlers for saving, adding, and deleting snippets. This makes it possible for unauthenticated attackers to modify plugin settings an...
- CVSS:
- 6.1
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 20, 2026