Recooty <= 1.0.6 - Cross-Site Request Forgery to Settings Update
mediumThe Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing nonce validation on the recooty_save_maybe() function. This makes it possible for unauthenticated attackers to update the recooty_key option and i...
- CVSS:
- 4.3
- Affected:
- 1.0.1 – 1.0.6
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2026