Rabbit Hole <= 1.1 - Cross-Site Request Forgery to Settings Reset
mediumThe Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the plugin's reset functionality. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request g...
- CVSS:
- 4.3
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 11, 2025